MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 8e18adc20814c415daaf27c741af456348442cd81e59215427aef359ad50675d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 3
| SHA256 hash: | 8e18adc20814c415daaf27c741af456348442cd81e59215427aef359ad50675d |
|---|---|
| SHA3-384 hash: | 51c2aa7c5b6186bb43d2012d5157d3af0e1618d2cae1a0528c7d9982ffdbff59a737d6813f644c52c2f51595f711894c |
| SHA1 hash: | 510aeec855ef283b2920bcec8caa9bd89715366a |
| MD5 hash: | ed41766336a4966ce21cffb4a6210dd2 |
| humanhash: | don-high-skylark-two |
| File name: | invoice and packing list PDF.rar |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 941'209 bytes |
| First seen: | 2020-10-08 14:13:00 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 24576:FVLSCu5E53MADjrLg1x7mPYItM//+Fgwvgp:FVLScMADjXC7aYzH |
| TLSH | C5153314CBF0BF2D5D419413A2C5986272B57E61CABF800F7E274D6C66EDBC184E3A1A |
| Reporter | |
| Tags: | DHL MassLogger rar |
abuse_ch
Malspam distributing MassLogger:HELO: server.nazarweb.org
Sending IP: 93.187.207.112
From: DHL International <abaran@diyarbakiroto.com.tr>
Reply-To: <donatella@fabiorusconi.it>
Subject: Re: Your Shipment invoice & packing-list
Attachment: invoice and packing list PDF.rar (contains "NJ6nrCbl0u1SzsI.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-10-08 13:45:21 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
MassLogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.