MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b3efee83e420509df329db90bf2e024655797605887c605f2553b3e8d4c82cf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8b3efee83e420509df329db90bf2e024655797605887c605f2553b3e8d4c82cf
SHA3-384 hash: 93358dd19cb4bded41efc85d4936a36620e4deb402bc74444544b82a42730bd3b949da3f666072b4f3eed05ebda53fcf
SHA1 hash: af8c6d46019981d4fc4ef994a1a3fcabf0bc4cb3
MD5 hash: 7b372f3d021b452c648229ba49e203fd
humanhash: stairway-white-tango-cup
File name:Order Inquiry List With 3D Artwork.zip
Download: download sample
Signature MassLogger
File size:865'372 bytes
First seen:2020-08-05 07:21:35 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:6ZEldpzLlUB5CuYLCJ2HvzM6WfEdz8HRK:NzC5vYLdzMrfE1
TLSH A8053391BDAE79C1C76D340FBC404626FBA6622884F2AB525FB72447F4350B2634D1BE
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: qq.com
Sending IP: 59.36.132.88
From: 电镀 <vcp@rtdln.com>
Subject: FW:RE:Re:【Alibaba_Inquiry_Notification】Jenny_from_Poland_has_sent_you_an_inquiry
Attachment: Order Inquiry List With 3D Artwork.zip (contains "Order Inquiry List With 3D Artwork.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-05 07:23:06 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 8b3efee83e420509df329db90bf2e024655797605887c605f2553b3e8d4c82cf

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments