MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ada5c3ff972fc1344418d6b6eaf304bbbc08fcf45c02cccbf6051126bed7cdc2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ada5c3ff972fc1344418d6b6eaf304bbbc08fcf45c02cccbf6051126bed7cdc2
SHA3-384 hash: 1c7f96173820e7ed6f9656898c5d192d5e7b11c6d5ed18b83d750b8393a5a77e0bc9ebc4398fb7023961e0fc0ec19e10
SHA1 hash: af3f3dde69d3858f193168a6b7251953d8764033
MD5 hash: e0996ba12618b89cec124d7b4e972b06
humanhash: lima-nevada-uncle-ohio
File name:PO_57859029 Keller RF0986.7z
Download: download sample
Signature MassLogger
File size:762'231 bytes
First seen:2020-10-15 11:22:38 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:DOKSD6xe61YLeFFF9W7TR94bSSoJZeOIi6QVLSdB+uQWvxttQ10WYzABpNdXkQ83:qKSD651yeFFqUbYJIVdkQS0WYzABpNdK
TLSH 07F4239B3B2766E9F2E63D40D04D42835AEBDE10D7DC79DC6386AE90B5150008FAF86D
Reporter abuse_ch
Tags:7z MassLogger


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: server.devbox12.com
Sending IP: 162.249.2.44
From: Nick.Hasell@keller.com
Reply-To: cinder0913@gmail.com
Subject: PURCHASE ORDER for KELLER GROUP - Rp07292 // Urgent PO 57859029
Attachment: PO_57859029 Keller RF0986.7z (contains "ljy6IHILgEpQLaz.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Burkina
Status:
Malicious
First seen:
2020-10-15 11:24:06 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

7z ada5c3ff972fc1344418d6b6eaf304bbbc08fcf45c02cccbf6051126bed7cdc2

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments