MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8d0d6ef5d40f5086af207d94212c1f8cc737f34eab3b84b8f14ff5a4a50b831b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8d0d6ef5d40f5086af207d94212c1f8cc737f34eab3b84b8f14ff5a4a50b831b
SHA3-384 hash: 4defc5c8825bda4f36e9ef290e86725174deabc6b0ed611a20b8de6a88b25cb9baa414d2c7985c847913d6abd11b2d90
SHA1 hash: 464ac8254a7a5a201efabf87ff9a59453743123a
MD5 hash: 60b25cd89c24b3fda7c83e1958eea943
humanhash: black-wisconsin-triple-tango
File name:scan copy.r00
Download: download sample
Signature MassLogger
File size:795'205 bytes
First seen:2020-08-17 17:34:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:FMQ0Uosp+uDicMRUUpVi8IYDhp8oZxw5DetD6K+uV09FR+Vn81:FMQ0rc+uDipRjTHfZxYel69aA+pu
TLSH 450523508BA4AB2867F4D743B1BB088B00608D5727CD327ADC60B257B4DC36EFAD55E6
Reporter abuse_ch
Tags:MassLogger r00


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: akriliktezgah.biz.tr
Sending IP: 162.221.204.210
From: Account Payable <info@akriliktezgah.biz.tr>
Subject: Payment Advise $ 112,500
Attachment: scan copy.r00 (contains "scan copy.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-17 17:36:07 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip 8d0d6ef5d40f5086af207d94212c1f8cc737f34eab3b84b8f14ff5a4a50b831b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments