MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7818e1826cadd824eea8e2a99d3c24addbb99c932930e70e4b07d58b6cbffcf7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7818e1826cadd824eea8e2a99d3c24addbb99c932930e70e4b07d58b6cbffcf7
SHA3-384 hash: ee998ec8f8fcfb0bc6b903a0a5d94d2a07f6344b87759bdf18b91c93480013af59e68b49c8a456f89fa65898a1aa0e66
SHA1 hash: 7586915be81bd88f176addedf01acd8c0d2c0c40
MD5 hash: 08adf16eeafdcf8f7a7764df869cc558
humanhash: emma-charlie-nitrogen-skylark
File name:2735727783652917237.r00
Download: download sample
Signature MassLogger
File size:744'159 bytes
First seen:2020-10-20 08:32:48 UTC
Last seen:2020-10-20 09:45:51 UTC
File type: r00
MIME type:application/x-rar
ssdeep 12288:ejtkEE0yBMPV91vL93o/CefQX4eNpQUG96vVPgFFeyCWFYZN3ZknvCkp3NhWPApJ:CPlLqCe4XrGLFF1YZN3+nqkp9hhqZ0
TLSH C9F4230E64F2709549853EE2224AF458A9CC75D4BF99CFB732F80980B796A494D8F7F0
Reporter abuse_ch
Tags:MassLogger r00


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: jtekt.com.cn
Sending IP: 156.96.62.59
From: kuang_xiaoqi <kuang_xiaoqi@jtekt.com.cn>
Subject: 回复: Order Confirmation
Attachment: 2735727783652917237.r00 (contains "2735727783652917237.exe")

MassLogger SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.CryptInject
Status:
Malicious
First seen:
2020-10-20 03:34:11 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 7818e1826cadd824eea8e2a99d3c24addbb99c932930e70e4b07d58b6cbffcf7

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments