MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae08792e686cd602ec9378e468d50dcbd456546867263bbced821b4fe93c73e7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ae08792e686cd602ec9378e468d50dcbd456546867263bbced821b4fe93c73e7
SHA3-384 hash: 117de13fa247ca66d33f50211106fe0c85fe3cf7dfdb69e6df6f71893ecbac3d0f01764438e7681dda0ae775d27b2e67
SHA1 hash: 72ea95fe78a70a2997e018db50355711db7c1460
MD5 hash: 1c350973bbcfb2d12a10aa0b6062959d
humanhash: carolina-neptune-leopard-lion
File name:Delivery Note - AWD 200038485852- 2349203300.r00
Download: download sample
Signature MassLogger
File size:673'908 bytes
First seen:2020-10-26 14:08:09 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 12288:KEx3yx/N8HaSxesWa3LEQfT2czFbX7afOASbwIXH8lH8UMsndoAMKobyBwEDuQRW:KEx3g/uHDxzpoQ7TX7af2bwIXwcfkobP
TLSH 08E423CBA842E49406F14E87233B1437A4A6800F9C7AD76F7611F069D737372A61BB27
Reporter abuse_ch
Tags:DHL MassLogger r00


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: e347122.name-servers.gr
Sending IP: 195.201.120.33
From: noreply@dhl.com <marimaxy_dhl@gmail.com>
Subject: DHL Shipping Notification
Attachment: Delivery Note - AWD 200038485852- 2349203300.r00 (contains "Delivery Note - AWD 200038485852- 2349203300.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Maslog
Status:
Malicious
First seen:
2020-10-26 05:01:47 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

r00 ae08792e686cd602ec9378e468d50dcbd456546867263bbced821b4fe93c73e7

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments