MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9d5c8e9c41ff08b0a3be489ac1ef0f014f2749ad0e3217af2e0665c514a072fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 18
| SHA256 hash: | 9d5c8e9c41ff08b0a3be489ac1ef0f014f2749ad0e3217af2e0665c514a072fc |
|---|---|
| SHA3-384 hash: | a80e13015a2d336dcf8dc265f5ab22b3511e0df4e49420e93822bdadf44a2997f0f29bab6938e10b4fa66b378e8987db |
| SHA1 hash: | 363b4ef390cc8fc3d2082206515c7dd3e740b381 |
| MD5 hash: | 38951bb0b8f73de25014f4d9ef401286 |
| humanhash: | stream-violet-arizona-potato |
| File name: | 9d5c8e9c41ff08b0a3be489ac1ef0f014f2749ad0e3217af2e0665c514a072fc |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 760'320 bytes |
| First seen: | 2025-10-09 14:03:40 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'003 x AgentTesla, 19'911 x Formbook, 12'332 x SnakeKeylogger) |
| ssdeep | 12288:DPX9cu16sWg7q4Ob+pvcDkeckeV4X5IO/z5EF3O+NXoF+U+C9nsshEAEH:DP9wiqupOd9eVA3a14F+wsuEAE |
| TLSH | T121F4020433AAEA02E5F28BF40831D7B407B87E4DB965E3065EE99DEF7835B419D41392 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
HUVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Malware Config
Unpacked files
2b1709a9c749ff0e6bca3643813dd090ac492a20104666259f65939d5e0c40b0
9d5c8e9c41ff08b0a3be489ac1ef0f014f2749ad0e3217af2e0665c514a072fc
e463f87a0c098ff8bcbc4c262e9eddf3dea51148d2ba9d12c64addb21e2ff978
ccbdec866c4dc5272bf35d9e08186c71031cfc63d37e45d96a35d69cdfb5dfe6
3b80f1666e8725435546d010c6f775ec852dd7691618236563e1bed1043da625
733c3e1e510fe841346e63a3728ec2d195951ef1b70992ee1de55e42f353a10c
82e9f638f4235a110559bbb2e9d83c4f72c23040799c80fde7e9503cfe66aa6e
6a2cefdd2b5810aef5388f4b23392847ae4abe6d4142ea7145e0afd04c00fcab
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | CP_AllMal_Detector |
|---|---|
| Author: | DiegoAnalytics |
| Description: | CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication |
| Rule name: | crime_snake_keylogger |
|---|---|
| Author: | Rony (r0ny_123) |
| Description: | Detects Snake keylogger payload |
| Rule name: | DetectEncryptedVariants |
|---|---|
| Author: | Zinyth |
| Description: | Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded |
| Rule name: | INDICATOR_SUSPICIOUS_Binary_References_Browsers |
|---|---|
| Author: | ditekSHen |
| Description: | Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers. |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_DotNetProcHook |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables with potential process hoocking |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables referencing many email and collaboration clients. Observed in information stealers |
| Rule name: | INDICATOR_SUSPICIOUS_EXE_TelegramChatBot |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables using Telegram Chat Bot |
| Rule name: | MAL_Envrial_Jan18_1 |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | MAL_Envrial_Jan18_1_RID2D8C |
|---|---|
| Author: | Florian Roth |
| Description: | Detects Encrial credential stealer malware |
| Reference: | https://twitter.com/malwrhunterteam/status/953313514629853184 |
| Rule name: | masslogger_gcch |
|---|---|
| Author: | govcert_ch |
| Rule name: | matiex |
|---|---|
| Author: | Michelle Khalil |
| Description: | This rule detects unpacked matiex malware samples. |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | RANSOMWARE |
|---|---|
| Author: | ToroGuitar |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_CMD_Powershell_Usage |
|---|---|
| Author: | XiAnzheng |
| Description: | May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP) |
| Rule name: | telegram_bot_api |
|---|---|
| Author: | rectifyq |
| Description: | Detects file containing Telegram Bot API |
| Rule name: | Windows_Trojan_SnakeKeylogger_af3faa65 |
|---|---|
| Author: | Elastic Security |
| Rule name: | win_masslogger_w0 |
|---|---|
| Author: | govcert_ch |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.