MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 766076d0180d65715e4e48b4efd9ee0d45de7d9a3652357c44bdb9d11e6b60b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 766076d0180d65715e4e48b4efd9ee0d45de7d9a3652357c44bdb9d11e6b60b4
SHA3-384 hash: b13ae3d3dc766eb09eea9facce68dfef7dda5181db6a3652e4463641c9fb42303a37d3264b76d7fb3df829aa327ce29b
SHA1 hash: 98ba241a513b5f12041006e7e4fdcf3327d80ce6
MD5 hash: f1e8acc7f21ea5d111603cd63e9539ab
humanhash: pluto-echo-fruit-december
File name:RE DHL Shipment Notice of Arrival AWB91-2340799.rar
Download: download sample
Signature MassLogger
File size:682'373 bytes
First seen:2020-08-31 06:01:02 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:GtRYYSBQynQ2hWlY63ArX7+Md9PlH7cHLCabb79GoBFEE39lHA7m:Gtm5bnQfY6QrKMdkfb99EEbg7m
TLSH 88E43371566358AF3C9FAADC6433711250C0B272B3E5678D33DB9B6D1F4832A6BA1D10
Reporter abuse_ch
Tags:DHL MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: auth5.cpanel.net
Sending IP: 78.142.208.30
From: DHL <info@sieska.com>
Reply-To: noreply <noreply@garanti.com.tr>
Subject: RE: DHL Shipment Notice of Arrival: AWB 91-2340799
Attachment: RE DHL Shipment Notice of Arrival AWB 91-2340799.rar (contains "KKKKK.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-08-30 20:09:45 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar 766076d0180d65715e4e48b4efd9ee0d45de7d9a3652357c44bdb9d11e6b60b4

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments