MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 889f57e4c5200656ce7a7b9c60157870771a3567430dd3cbb6093200a07d8e80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 889f57e4c5200656ce7a7b9c60157870771a3567430dd3cbb6093200a07d8e80
SHA3-384 hash: 996d244516264d6a800880e35d5bb1c131a976c83871bd8189ca2cddc073662f0dbf74f436fcf34ffa81af1107949f50
SHA1 hash: f68886310d9b3cac6f87213ff901be6518fe3097
MD5 hash: 61e35c7da2cdd36919ba174eb0f85e11
humanhash: bakerloo-cup-jersey-hot
File name:ORDEN DE COMPRA-pdf.7z
Download: download sample
Signature MassLogger
File size:566'354 bytes
First seen:2020-08-12 15:29:10 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:EUX8t3gNtrEVIXUuELDuGmxRLb0h2xVTU+QUtpjnT:X8KNtvXUuEfmHxVTVQspjT
TLSH F3C423CA232E7D8FD585D22CEA5BB031B678E83BC80651C2577176A236B05745F8F187
Reporter abuse_ch
Tags:7z MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: linux1537.grserver.gr
Sending IP: 185.138.42.92
From: Reservas Abra Pas <abrapasreservas@cantur.com>
Reply-To: Reservas Abra Pas <baeutyslondon@yahoo.com>
Subject: NUEVO PEDIDO DE ENVÍO A VIETNAM
Attachment: ORDEN DE COMPRA-pdf.7z (contains "ORDEN DE COMPRA-pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-12 15:31:05 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 889f57e4c5200656ce7a7b9c60157870771a3567430dd3cbb6093200a07d8e80

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments