MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 688a9da779431fa2ae864ace6d8fa62ffc14c67fc8f36f30d03f0bf66a4c2404. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 688a9da779431fa2ae864ace6d8fa62ffc14c67fc8f36f30d03f0bf66a4c2404
SHA3-384 hash: 9965bb26df44f8b615f8ebd99fbec405d1ac4544115a72e2ea849ad4277e2575cb664972b69eb1c113d464497df3a5a6
SHA1 hash: 2d3c19fe75dde59a60cd79bc433b264ba7c91995
MD5 hash: 4515c5e6bfd231d0337bb8c15f4b460c
humanhash: hotel-sink-double-berlin
File name:FV00620224400 009384766589.r15
Download: download sample
Signature MassLogger
File size:691'774 bytes
First seen:2020-10-16 13:01:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:YqRBOcrNMGHaetFvFu9IsiTzpexDHEdUMJegwTInINWrJMETLYhKcK:YirrNM4+9UWk1ewIIJMWL6M
TLSH 5FE433A97C8C40B5D38B53B32FC42E9714C3C56651CEBAA3B3F89C257F809AD5854A2C
Reporter abuse_ch
Tags:DHL MassLogger r15


Avatar
abuse_ch
Malspam distributing MassLogger:

From: DHL EXPRESS <maria_dhl@gmail.com>
Subject: DHL Failed Delivery Notification
Attachment: FV00620224400 009384766589.r15 (contains "FV00620224400 009384766589.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar 688a9da779431fa2ae864ace6d8fa62ffc14c67fc8f36f30d03f0bf66a4c2404

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments