MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4fade99690c723798caf5f96673fed6674255b5ded6e426797da0513e864a7f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4fade99690c723798caf5f96673fed6674255b5ded6e426797da0513e864a7f5
SHA3-384 hash: 766833006069ad81664d1d04f992ac07e5bf740dc80049d934da1d283013158ea1ca4bedb067da5daf3cd9457e856a6e
SHA1 hash: a096d8c222b17465584100dc88072b9fd3d59bea
MD5 hash: 4bc936494855f88fd34131a170a20ad3
humanhash: mockingbird-echo-washington-maryland
File name:Kopi af overfa¸rsel 03.01.2021.7z
Download: download sample
Signature MassLogger
File size:772'134 bytes
First seen:2021-03-02 07:54:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:+g1pqg6rxWoniM9s0qu8GEb4Aj0tpHeFawY+YRwRFfAMsOXqxZunlXvRYdLdzQo1:1LkxWuDy0unbybIVRFfAMJAM+dhzQMcc
TLSH C0F4330DDD8830BC3853A84C24DB8A69B1DFB5F2C9A7A7FF2BA909965315EA0B401D45
Reporter abuse_ch
Tags:7z DHL DNK geo MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: websrv01.zoolab.it
Sending IP: 89.46.192.135
From: Aya Bjorn <ayabjorn05@hotmail.com>
Reply-To: Aya Bjorn <swatil-bom5.vsnl@outlook.com>
Subject: Råd om overførsel 03.01.2021
Attachment: Kopi af overfa¸rsel 03.01.2021.7z (contains "Kopi af overfa¸rsel 03.01.2021.exe")

MassLogger SMTP Exfil server:
mail.acisn.pt:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-03-02 07:55:15 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 4fade99690c723798caf5f96673fed6674255b5ded6e426797da0513e864a7f5

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments