MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d0d9f6688e79b8735cc0ca9706cd515bd3900c20e485e7af1d75e72cafd23ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5d0d9f6688e79b8735cc0ca9706cd515bd3900c20e485e7af1d75e72cafd23ae
SHA3-384 hash: 55550d8cfc39a24eb2786483297c619a680a8acc30bb58156980ffdaa07f0ac0ef7aae4481be3453b2f74dddf11e36f3
SHA1 hash: 7efa8d39a647f44d254e46bb8b87e333e18d414c
MD5 hash: 9bf28f49f0b83d2f519ce37ba23d5a5f
humanhash: ten-magnesium-ceiling-pizza
File name:RFQ-NOV-2020.r00
Download: download sample
Signature MassLogger
File size:562'149 bytes
First seen:2020-11-05 09:24:35 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:0zmqpqKHt/W2Tm6LPFa7Z7HPi3STJwfyhUH:cqat/NPLPs79PDw+C
TLSH 5EC43398F899DB8F74CC4F65D316251979A429B00B4ECABEA4A4BCA4DC42027ED7DC4C
Reporter abuse_ch
Tags:MassLogger r00


Avatar
abuse_ch
Malspam distributing MassLogger:

From: Luna Cheng <salespnh@galileocambodia.com>
Subject: REQUEST FOR QUOTATION- ADNC TAIWAN Please quote your most competitive rates
Attachment: RFQ-NOV-2020.r00 (contains "RFQ-NOV-2020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Infostealer.Maslog
Status:
Malicious
First seen:
2020-11-05 09:26:06 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 5d0d9f6688e79b8735cc0ca9706cd515bd3900c20e485e7af1d75e72cafd23ae

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments