MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a7399c8c9e87373ce7148c611298f89756d4a209fb77b7969854718d87e469bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a7399c8c9e87373ce7148c611298f89756d4a209fb77b7969854718d87e469bd
SHA3-384 hash: 72304bb70a8dc82257bf6deb51e892b673d8095907b9cd2420db491be9d49f2cd1a23002e85fbd11b7a4be8541904a68
SHA1 hash: dc4973587da1af27fe876fe2dfe33abbbcc22798
MD5 hash: 9d410a23d4d8e3494580f264287c2e38
humanhash: nineteen-xray-mars-may
File name:purchase order_pdf.zip
Download: download sample
Signature MassLogger
File size:773'609 bytes
First seen:2020-11-20 07:58:09 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:pDqAT97Gt7GyCS7ev0K4Di/H4Do53H7OqR4W4kDQjbS2RPTd+O16EmxbSq1H6T:pDnZyt7vCSKv0V2f4EX73R4W4kDMSscw
TLSH A6F433D7132C0F6D62F31923F65C63C2DAF897091EB765A42A39BC31F1A55A43E64C82
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: zoz0.209.xzov.ml
Sending IP: 68.183.145.95
From: Dmitry Novichenco <sales@imlamp.com>
Subject: Updated Quotation
Attachment: purchase order_pdf.zip (contains "purchase order_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Sudloader
Status:
Malicious
First seen:
2020-11-20 07:59:09 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip a7399c8c9e87373ce7148c611298f89756d4a209fb77b7969854718d87e469bd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments