MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 14


Intelligence 14 IOCs YARA 7 File information Comments

SHA256 hash: 66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
SHA3-384 hash: 5e5c96eb551204423478d788aff54e59813f73c98956fe57bc05649651243e6340a82fda4ab81699e66d88d30b981b1f
SHA1 hash: 7baeb297a50bd49bb6e1500d21612e6493c39ada
MD5 hash: 20be611ea4964bbca64e51b103a506b3
humanhash: magnesium-pip-hydrogen-winner
File name:SOF-41593-21052024112851.exe
Download: download sample
Signature MassLogger
File size:530'952 bytes
First seen:2024-11-15 04:30:04 UTC
Last seen:2024-11-15 08:19:10 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'740 x AgentTesla, 19'600 x Formbook, 12'241 x SnakeKeylogger)
ssdeep 12288:03HI6D3+/w/urQU6PgcnQACyaX5dPIhckBTj+kR:2HIr42rhxaiym5dwv
Threatray 2'691 similar samples on MalwareBazaar
TLSH T1A2B401A6EA56E443DED9077402B5DBBA46335E8DE420D3179BFCECDB7C41B2A3818241
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
File icon (PE):PE icon
dhash icon 0884cc3860ccd420 (2 x Formbook, 2 x RemcosRAT, 1 x MassLogger)
Reporter threatcat_ch
Tags:exe MassLogger

Intelligence


File Origin
# of uploads :
2
# of downloads :
438
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
SOF-41593-21052024112851.exe
Verdict:
Malicious activity
Analysis date:
2024-11-15 05:04:41 UTC
Tags:
evasion snake keylogger

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
injection obfusc shell
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
DNS request
Connection attempt
Sending an HTTP GET request
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
packed packed packer_detected vbnet
Malware family:
Snake Keylogger
Verdict:
Malicious
Result
Threat name:
MassLogger RAT
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
AI detected suspicious sample
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected MassLogger RAT
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1556212 Sample: SOF-41593-21052024112851.exe Startdate: 15/11/2024 Architecture: WINDOWS Score: 100 46 reallyfreegeoip.org 2->46 48 checkip.dyndns.org 2->48 50 checkip.dyndns.com 2->50 56 Found malware configuration 2->56 58 Malicious sample detected (through community Yara rule) 2->58 60 Sigma detected: Scheduled temp file as task from temp location 2->60 64 10 other signatures 2->64 8 SOF-41593-21052024112851.exe 7 2->8         started        12 AwudofIDaGp.exe 5 2->12         started        signatures3 62 Tries to detect the country of the analysis system (by using the IP) 46->62 process4 file5 38 C:\Users\user\AppData\...\AwudofIDaGp.exe, PE32 8->38 dropped 40 C:\Users\...\AwudofIDaGp.exe:Zone.Identifier, ASCII 8->40 dropped 42 C:\Users\user\AppData\Local\...\tmp34DB.tmp, XML 8->42 dropped 44 C:\Users\...\SOF-41593-21052024112851.exe.log, ASCII 8->44 dropped 66 Uses schtasks.exe or at.exe to add and modify task schedules 8->66 68 Adds a directory exclusion to Windows Defender 8->68 70 Injects a PE file into a foreign processes 8->70 14 powershell.exe 23 8->14         started        17 powershell.exe 23 8->17         started        19 SOF-41593-21052024112851.exe 15 2 8->19         started        22 schtasks.exe 1 8->22         started        72 Multi AV Scanner detection for dropped file 12->72 74 Machine Learning detection for dropped file 12->74 24 AwudofIDaGp.exe 12->24         started        26 schtasks.exe 12->26         started        signatures6 process7 dnsIp8 76 Loading BitLocker PowerShell Module 14->76 28 conhost.exe 14->28         started        30 WmiPrvSE.exe 14->30         started        32 conhost.exe 17->32         started        52 checkip.dyndns.com 158.101.44.242, 49734, 49738, 80 ORACLE-BMC-31898US United States 19->52 54 reallyfreegeoip.org 188.114.96.3, 443, 49736, 49739 CLOUDFLARENETUS European Union 19->54 34 conhost.exe 22->34         started        78 Tries to steal Mail credentials (via file / registry access) 24->78 80 Tries to harvest and steal browser information (history, passwords, etc) 24->80 36 conhost.exe 26->36         started        signatures9 process10
Threat name:
ByteCode-MSIL.Trojan.Znyonm
Status:
Malicious
First seen:
2024-11-15 04:31:05 UTC
File Type:
PE (.Net Exe)
Extracted files:
6
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
collection discovery execution spyware stealer
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
System Location Discovery: System Language Discovery
Enumerates physical storage devices
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Unpacked files
SH256 hash:
b6fe518ed8ca7ee32f79bb5dd52ab8250cc595d1aa8daec123cef383c6b0bdb6
MD5 hash:
b45e3c4c10da3da0c69e2f90dc3dfb10
SHA1 hash:
61a36473ced38978793a9af1aea1fc528eebe457
Detections:
win_masslogger_w0 win_404keylogger_g1 INDICATOR_SUSPICIOUS_EXE_TelegramChatBot MAL_Envrial_Jan18_1 INDICATOR_SUSPICIOUS_Binary_References_Browsers
Parent samples :
2e60e1e443fe9ccbc167bd093cbea48ed49743648f5c8df81c9d7356ac499194
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
ad2f3629f617763f45abc1be39c4a28f581ca8d0efb97e3bde2ad33106714c85
0004912ccca96809295d0383d2febcd100a386ed262d9912f1a02e886ae460c0
195ee9a9f96abb146c2c217c659c7cd66093d607b9a64a1ffe976a32eee81b2c
4e007a23a0658f7417c1767bf2f2a0a3722853216e9a00489f79d57b555acc9e
f68c0c40aa651d080967ea4ea3c389fc1e3dbafcd097ac10f01374d0f6ae52d3
862a367b1e130dc47d08a2d4ce26bec8d85196f00c1a3f6c0df4fc5f099139cd
29ce0132efcb5e1aad146065672d83b6b4ced076f1c91a851c8b34a30e7e08eb
45def37a33ac8c66332d64929636aa908916c5a4c4b17ff5724de5564d066105
593995d24730f261cde9c772b7fddbbc57b02d36418905ba7a95b78609d4a258
8835d6d5566c121cb4fd76ef710de856b803636037b510524d3de684071cd1ad
9155862979f292ea527e4107a7143bd9b54c66511a1aa1b04a06f924a4ed901d
be9412060a9d41f496e907a637096255fa848a8ecb4bb4b35043f2e71ca871f6
8de72052a7f6f26cdf6b3a1850902acdd6856fe29b94871fd9eb3fceca479fa6
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
5f97099c9597917ad3091e70910dc93ded0181185c1878fa4dfffaf540b46e4b
ccfaea5dfcfb212dff4902b0392b7b793bec6f56c5d7162fca472ed00995d381
c5f3533849c988dc9812857c7a8e6359d82cf650955eec6d14661426e62bbde1
fc555917ce12a41761d6e21ef399d5be7dce2da3d15a05b2ce3fff10abcd77f9
80b3c8d9dcccf09f2cd697875d417ecfd90dc7ce3132ef10bc5d6f48510d19da
185a716f245f4951e997e91ca747ec2f52acf4fb0adf594bccd9c8acbfacf677
b996d0418d6d8ac7d8f9ce4d09d0eb1f0fd1b30d733499742a41a9c6930521b4
e5406c9136408ddbe90ec00c45b1291e3e847826ce1be6c39b77327d135e57c2
8ef455d1383249717a5d6215a98c176da08d5cf9f2d70f6d3ea24368b36b00c5
038849db19818c7136fe0a551b3f1b9ab11d51390ab2f4197f9f7c5ff16f6a8f
987d80fbc03ed5f7612a742982367ae5f354237968d23b2fe1cbe9440946497d
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
01e631c29a801330b7eb8f5904e171a8d47b044754153792955a459c25db112b
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
2f712c6b725905241f86c0a76963dc5053e59d0dbd1b0396dc2e88c3d94f54ff
1ec8e13c55c7d0114d1877cdce2e18be355218edce5ae2403ff928305799885b
5d19080b4f02064df1e03553721cb9269413ef21e5bee832d9dd5688f01db5e6
8de4312c046f3b3586dbf7a813d5678c2ad5dd319d476f4d64b403dc0d45f714
1e12346e4000bfaebac977089464afeb82b3729a90bb6ffd66dde49b2da297e2
8b903abd92011f515abe01bde91dbf27d2f8037e7712be038bf7bdad420b5e6e
ef522b08a1410eef91c4e03d3241eb012720d8e16ca363dd93a48c2b5c92df1f
f99d68393189fed84f6b667127e531a5f9efc410598335eb06a6b973462237e5
a5c29abda5dbd2006117b82fdadbb70f42354298b49019b73c36e31e8c6bdedb
7f4009e7a332b49ab49007e5cf74a87a6a7bf5a115a0acb621ff8657908ea2b3
81772deba6bfc78c34c1f83ecf47c84337e0b7592f96c6548b3e865a0a424eb3
0f0797053ff7a7b8e0bc5e75a5cd8e2eb91739101486374e4209c29a92fc2d66
SH256 hash:
131e55d1d754713ee87cdf2e5e0399705098002ecef72826f8dff7c603711248
MD5 hash:
45ff54f4cdc18cbeeb5a3bbe45e4f883
SHA1 hash:
32b3e5c7b7bc9a47ef9ccbd7892eda98220ac10c
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
7852d1abd54b4575421c9e18e92afa2c16134d665caaded3ec9715471bdcef6f
6563b16904df3e6e15a66292bee241bee856ab8668da10d15217d7e19c612e53
2ca6eee7501a3f4d5b825e7e30746fd3916b3ea91ff9f52e3eb97273ce587931
d0063dabacc1569353b846cd664cf979784b4855d03e6ed4fc0ef7f013a0bad9
c681443c1d8c5ed6ce5b8e4ace22cdd72b18d9eaf3673a0a3a66847aa6f4bf29
f7cfd8a77e099b053a939902b4bc371cf0660070287b7f9f89971181d36be10e
2d139feda3a6ff2f5710f76273a3b004e042cc637f15f18c2bcc4ad0213add28
98392e19d221d0f5440cdd47983162865a18f31bd1d3dbae289e11acdad4b2c6
4003ba5752bd4c4969c49c34e65f594c8ae977ee7a06fd96681184308b72d3d3
7f80c742d679b5972a77e5216ca8f0bed855362976e0c5b813be6fe30ccd5df5
c8709a132b063bfb746899511930b50ee84019dc45206333b74cdf702963a187
47b2857258f743ca87c19d38ebec95a1bc1c0490341ad9f08560529bfcb861e1
9c67693c262b17c39bc1eb3c9b9a7861342c7b01a72ee76e9df1826d8776a686
34956fb0874a7093f7e246b475a97acc90e312c3c762a09f69d9933b0837f59f
3f98154dfa957eb333cae8aea1c9d03234145c5f7c72a185c3e95500a07f214d
224c47ef077b428bd96989875e00573896c4f487f1ac78a6baa81e1741d7e5d5
b7df6d57fa0d03e8b88e410b7e3f9e9b2a3f1ea1ed7da20772b5ac891901b973
fc05c8cd30f572b0db13bc5189c99ce499f133f7b65167c06518638c26623a81
4108dbe3814c32378cfc316c1c9f0a40dfa83111c5ae29ab617b03da0ec35d8e
0b606f6d0ce44922bf456bee5e6e8acf1b343521b2d5d4c5838926cc0484e052
97aa70078b62693b212b1b210268a10fe423294f7ca03f922fe160a4708dfc91
a99e96240277999d6ac2c51b1071298e9488a4e08a24f3ac934c8c1d5f68fa0e
eaa050e146a491a37439f2c6e8be17f57b97c6f6ed12c9eaf982e55810031483
4a78c8f9b9321dd93c0e1c9e325271c434aa194d67e9d63b73c66c054d44049f
b9311758998b5ea517d97a07a4e66a2616ef9395eef50dae210f6246c7fe02ae
6e8bcfa79edd86fc5d01099d1343962ea8c3a64ec8af2e7959a3df3775f82fdd
d079862ef124c7736c9321485c30fa19a7c944ac81bc683d123c1aa6c50414a5
62c012d00a605e319f4b61150151a4d811b80472e91ebc4bdebd5d98035250d2
c91b31fb14eff751d72b07b53b3d1d71a63dce9cc61bbef4c939cbd671090585
d097aece3afaf2eeafce3fea88dc99e98ef31465bb9216fbc4bbc0c649dea94c
cbe1d843259a92581d16088969b0ed1758866626b4ae37e7445abe6bf099f155
b94860a81a9afcb57b5e604c4008381cc550376a34d8f79f7381360a5573d756
972d31f6bff6eed33197d77be4cf2027535bd64d42965c207c6e541257a4e112
27e9d8399b11830c69e45b1d2f37dbde869ff3ec1185ea640c209399fb1d737b
1d7608383da2756b65cc19e91419acd47290ee520b76a760bb5089f1738a7778
e3d34efa98ab95227b84ed48a65ce73b3875f3c0ceaab5ac821fdecb37392eb9
653d0521ebc0b85438a6d6d6e95b0bb5cf4c3dd5395a4751285eeac9424ec4bb
7472c3e5664fd075431ac23ecb337cd7cff53da3456dc4b3597c7b7552ebfc3c
8a2e2937cc4e90870343522e1e0440751defe875a0c12fc0fac74100a0eec7c9
c39e46fa96e4724e308a2597cea9822213c22919b069bbd7943ac12c39230520
63703694c54d43f82c63cb2f61964b693a73bcf6f013cda7e226d29a77d0c82b
22b0dcc30c169644100916d06c39328f35a546a5b4a55a196dcc4d2b6a8197de
edb8cc2548ed59dc491c0a1cb0b4907a2235b13bbe06a880053bbab544f91386
8de72052a7f6f26cdf6b3a1850902acdd6856fe29b94871fd9eb3fceca479fa6
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
9164dd5f64ab6f63526f744cf663cffcd635eb3645c45e8ebf8449116ce118f6
867c2b0b46aa21ddd3f73b517c673a7487bc254f0cc61f0a0183746c216ef3d9
6eaf9b6af911a7995d490906ff5d42a36a47e4b1d4510f6fc33c7cdab2c80aae
9ee4e1e0703b2bcd5e827daa1ae9495abab382f7d577c7854f2a528712d19198
9ac9f2ea6f74be133ff46c0b9bfea09455c4b5f0865f88fa19b4b42c71583ac0
c087790833ae259686895407c9f60de7ef7614956fae617761998a4a5467f60f
4d9269d0c5706adc5a898408e788b15e5cdf9e490ccdec4c52aec64b8f8c63a2
a70404d3f9f9fc5e48ac266731e1b3b5a780ae9b0ba15e865418e5f908aa6178
fd12d28d6b8030ec8e3d28c13ce562dc0f42b085806401b02a1155a6f44eb19c
b3a40331524394846d2782f1e52e1410ce1681283f8c715373bab73c84fa30ec
7943aab15dc5804448102c5c1fc5341b65708bff970773e25f0f27d807e90d29
7e0e0bc4dd67c9e124e88b86e5dee610fc737bc40102656888772b4ded881704
SH256 hash:
894771e65fc30d2c3b72f0ee6e6b2a6786067dfaea62631acfc32e2bda6ddc10
MD5 hash:
fe918f4fecb2a9f755e52a93c902a217
SHA1 hash:
3005e68de22a71a87352c1d93c3701f31cc4c73c
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
MD5 hash:
20be611ea4964bbca64e51b103a506b3
SHA1 hash:
7baeb297a50bd49bb6e1500d21612e6493c39ada
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:NET
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

Executable exe 66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (GUARD_CF)high

Comments