MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 5b4d0d76bf34a4612d8d9b4b7a127c76528022517b6b39b3a78bc7631bc4cbaa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 18
| SHA256 hash: | 5b4d0d76bf34a4612d8d9b4b7a127c76528022517b6b39b3a78bc7631bc4cbaa |
|---|---|
| SHA3-384 hash: | 775ba13a3f3fe19a4103e33bdb28a90d83674568a0b0b14595e69c8b060ce946f64d3302188c38750842d951ac9e022c |
| SHA1 hash: | b959e881835209b58e5edbbe3b2d7e919dad751d |
| MD5 hash: | c98ef053cc49cae662fa77ad83dc41d4 |
| humanhash: | cat-batman-eight-early |
| File name: | 5b4d0d76bf34a4612d8d9b4b7a127c76528022517b6b39b3a78bc7631bc4cbaa |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 716'288 bytes |
| First seen: | 2025-05-09 12:36:31 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'661 x AgentTesla, 19'474 x Formbook, 12'208 x SnakeKeylogger) |
| ssdeep | 12288:dsf2Thr4/zKF+HITGfzG8WI73XGPVSZ2IbZL3EY95KaGbyv:6fKhr6HITgvbGPMZFZL193G6 |
| Threatray | 920 similar samples on MalwareBazaar |
| TLSH | T162E4AD452D758409FCEE0EB0042892F75AE2ED876A21952BC7957F57B23630CBCCA6F1 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| dhash icon | e194aab2b2aad421 (10 x AgentTesla, 4 x AveMariaRAT, 3 x Formbook) |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
d80507a1b8196778bf4bd776576b4dfce576c5c489a38912de8ff2e6bc57066c
426a50e79f5b9668b5de1ac553169cbab2e6472ebe9ca6950b5be01454cd04a0
99eb21753db52508e65ced48f7f5dae3fb00a288e22dd1d54df7bca78f394bb7
85eb3041d52eb735c82cd60b3a9fb25d404de4abdf04fa920c81ba400032e881
03ddcfc0bd5eeddecae7ea59eb8bb9bf08a55a1f03784a3e09b99df597149bf2
5b4d0d76bf34a4612d8d9b4b7a127c76528022517b6b39b3a78bc7631bc4cbaa
200028d1284bf0590155f241c66bf26c43661758386856a23b640f92da28833a
03144acbec20eee89dd5335fb02facd0da97ca6e4c3e08b6b0adfa58aafe2533
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.