MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 70b9faab5ed08bb8a13fd31713c698e18ca4f504055deae086ab1a9bf7007b47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 70b9faab5ed08bb8a13fd31713c698e18ca4f504055deae086ab1a9bf7007b47
SHA3-384 hash: a7ccf8d7ca65389529ad9f8ef9e1fe4f5e63365b07c425a49dc0ad475baa187b1d36a5cb2c7d1fd6998826d80dcdae4f
SHA1 hash: 5ad9a595bf6effc2a1c65dc4c8423fdd17416d37
MD5 hash: 2e207f4049944bb0ec93fcd07f04fc3a
humanhash: charlie-winner-minnesota-island
File name:Syed Kaleel CV.zip
Download: download sample
Signature MassLogger
File size:739'991 bytes
First seen:2020-10-28 08:56:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:Q4g3Ole+vTG0KngCybSmwCmDHCUyffpCxToe/hFI+QJxY/AAZKY0vh/H/3BZjZyO:dpln2ObS5jCU0fGl70OoYpUH/jjZtRzj
TLSH BCF42351C0309BD8CD29AB69372D5BE8438D1CB2DB5F90C8965597FA6723F58D3AC070
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: gmail.com
Sending IP: 156.96.118.35
From: Syed Kaleel <SyedmoKaleel212@gmail.com>
Subject: Accountant with Experience
Attachment: Syed Kaleel CV.zip (contains "chibyke11.exe")

MassLogger SMTP exfil server:
mail.hkoffice365.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-28 06:32:26 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 70b9faab5ed08bb8a13fd31713c698e18ca4f504055deae086ab1a9bf7007b47

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments