MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e18adc20814c415daaf27c741af456348442cd81e59215427aef359ad50675d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8e18adc20814c415daaf27c741af456348442cd81e59215427aef359ad50675d
SHA3-384 hash: 51c2aa7c5b6186bb43d2012d5157d3af0e1618d2cae1a0528c7d9982ffdbff59a737d6813f644c52c2f51595f711894c
SHA1 hash: 510aeec855ef283b2920bcec8caa9bd89715366a
MD5 hash: ed41766336a4966ce21cffb4a6210dd2
humanhash: don-high-skylark-two
File name:invoice and packing list PDF.rar
Download: download sample
Signature MassLogger
File size:941'209 bytes
First seen:2020-10-08 14:13:00 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:FVLSCu5E53MADjrLg1x7mPYItM//+Fgwvgp:FVLScMADjXC7aYzH
TLSH C5153314CBF0BF2D5D419413A2C5986272B57E61CABF800F7E274D6C66EDBC184E3A1A
Reporter abuse_ch
Tags:DHL MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: server.nazarweb.org
Sending IP: 93.187.207.112
From: DHL International <abaran@diyarbakiroto.com.tr>
Reply-To: <donatella@fabiorusconi.it>
Subject: Re: Your Shipment invoice & packing-list
Attachment: invoice and packing list PDF.rar (contains "NJ6nrCbl0u1SzsI.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-10-08 13:45:21 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar 8e18adc20814c415daaf27c741af456348442cd81e59215427aef359ad50675d

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments