MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 86c42bf441778e03f0cba48874b6a62c50e756f8057e4c61ee21895241a274c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 86c42bf441778e03f0cba48874b6a62c50e756f8057e4c61ee21895241a274c9
SHA3-384 hash: 71d68d44ad701ba6799331751add1cc998b7957daa7b43d3385f385227e58efec3f202770233912d3e359e816815edbe
SHA1 hash: 90fdab720e814335a0f165575f53f65dbda22e59
MD5 hash: 4c80c17edc15aa6287aec88e84c1e3db
humanhash: chicken-hotel-freddie-florida
File name:Payment3954300111-pdf.7z
Download: download sample
Signature MassLogger
File size:970'740 bytes
First seen:2020-10-05 13:25:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:6JfIJuPIhs3AI4IdluUMl5FSz9m1p1wUjr7Hs0ahZnW0:qguw2f4FUMl/Szc13LXY0ahZW0
TLSH 262533BD212DDAC2978C4AA4EF0D660E8FD945F270B5116C64055E92827BCEE7B4F383
Reporter abuse_ch
Tags:7z MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: lvps92-51-134-34.dedicated.hosteurope.de
Sending IP: 92.51.134.34
From: Frédéric AUBERT <contact@az-ouvertures.fr>
Reply-To: Frédéric AUBERT <baeutyslondon@yahoo.com>
Subject: PAYMENT UPDATE
Attachment: Payment3954300111-pdf.7z (contains "Payment3954300111-pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-05 11:12:51 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 86c42bf441778e03f0cba48874b6a62c50e756f8057e4c61ee21895241a274c9

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments