MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e99f5e3d4efc4aece3e91b7cbbbcf2ffcb21072a8f14bd874047383e77fe5ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 7e99f5e3d4efc4aece3e91b7cbbbcf2ffcb21072a8f14bd874047383e77fe5ab
SHA3-384 hash: 0571eefe642333de783e86ac8bf90d0f1fc6deafbe759aaa3137ee8e4a2fc5c7cfca1813486a38ec69863fa1a58da38b
SHA1 hash: a806cfe9b0f5a65f211b68fb0287e5fb5a5e7b62
MD5 hash: c409efde87d14f7a02f67742df2b28c6
humanhash: nuts-fish-undress-green
File name:April Offer-SSQ2026.4953.JS
Download: download sample
Signature MassLogger
File size:3'415'178 bytes
First seen:2026-05-27 22:59:03 UTC
Last seen:2026-06-01 12:28:23 UTC
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:1xJ0/B5hVcHXI/GNLQIXblXuhvmQE6BCBEFQ+lbiyCTSkm6QUCJUrlA+KSW:1wBlYXtNTLEjEYCBFGbmTSkm6YU5A+y
TLSH T1E1F5E5608B92A132B320D74D497ABF38A41F598764E5DF01301DEA38395EC67931BBE7
Magika javascript
Reporter jahlives
Tags:exe-in-archive js MassLogger spamtrap

Intelligence


File Origin
# of uploads :
10
# of downloads :
143
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Score:
90.2%
Tags:
backdoor blic hype
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dropper evasive obfuscated obfuscated packed repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-05-27T11:26:00Z UTC
Last seen:
2026-05-29T21:37:00Z UTC
Hits:
~10000
Detections:
Trojan-Spy.MSIL.BPLogger.sb Trojan-PSW.Win32.Stealer.sb PDM:Trojan.Win32.Generic HEUR:Trojan-Downloader.Script.Generic Trojan.Win32.Shellcode.sb Trojan-PSW.Win32.Stelega.sb Trojan-Downloader.JS.Cryptoload.sb HEUR:Trojan-Dropper.Script.Generic HEUR:Trojan.Script.Generic
Gathering data
Threat name:
Win32.Trojan.Redirector
Status:
Malicious
First seen:
2026-05-27 18:16:46 UTC
File Type:
Binary
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
donutloader novastealer
Similar samples:
Result
Malware family:
masslogger
Score:
  10/10
Tags:
family:donutloader family:masslogger collection discovery execution loader spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Detects DonutLoader
Family: DonutLoader
Family: MassLogger
Malware family:
DonutLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments