MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 13
| SHA256 hash: | b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485 |
|---|---|
| SHA3-384 hash: | 0219acfb9fd8aed575167ecee810125528d1f0779263e41a62794a902ed2369ee1c7b2961ab0e5a5edbd43d91194144e |
| SHA1 hash: | 3bfcc863d987177120befb4fc8ad82380b06093b |
| MD5 hash: | b3647fa45593f46fffca9bd579e78ec7 |
| humanhash: | vegan-floor-alpha-hotel |
| File name: | 14 EKİM 2024 HAFTALIK EKONOMİ BÜLTENİ.exe |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 536'072 bytes |
| First seen: | 2024-10-17 07:31:16 UTC |
| Last seen: | 2024-10-17 08:39:42 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'653 x AgentTesla, 19'464 x Formbook, 12'205 x SnakeKeylogger) |
| ssdeep | 12288:d4REeG5tXA2aiit6q/KrpuAMUs/2ceszpwQNkR:GRbG5+siP/kMbk |
| Threatray | 478 similar samples on MalwareBazaar |
| TLSH | T1B0B401F113A9DA16D5AD47F60070DA32DBB5AF8FB021D30A4DEB8CEB794078428946D7 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 2b3033c607391ba6 (3 x Formbook, 2 x RemcosRAT, 2 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
ad2f3629f617763f45abc1be39c4a28f581ca8d0efb97e3bde2ad33106714c85
0004912ccca96809295d0383d2febcd100a386ed262d9912f1a02e886ae460c0
195ee9a9f96abb146c2c217c659c7cd66093d607b9a64a1ffe976a32eee81b2c
4e007a23a0658f7417c1767bf2f2a0a3722853216e9a00489f79d57b555acc9e
f68c0c40aa651d080967ea4ea3c389fc1e3dbafcd097ac10f01374d0f6ae52d3
862a367b1e130dc47d08a2d4ce26bec8d85196f00c1a3f6c0df4fc5f099139cd
29ce0132efcb5e1aad146065672d83b6b4ced076f1c91a851c8b34a30e7e08eb
45def37a33ac8c66332d64929636aa908916c5a4c4b17ff5724de5564d066105
593995d24730f261cde9c772b7fddbbc57b02d36418905ba7a95b78609d4a258
8835d6d5566c121cb4fd76ef710de856b803636037b510524d3de684071cd1ad
9155862979f292ea527e4107a7143bd9b54c66511a1aa1b04a06f924a4ed901d
be9412060a9d41f496e907a637096255fa848a8ecb4bb4b35043f2e71ca871f6
8de72052a7f6f26cdf6b3a1850902acdd6856fe29b94871fd9eb3fceca479fa6
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
5f97099c9597917ad3091e70910dc93ded0181185c1878fa4dfffaf540b46e4b
ccfaea5dfcfb212dff4902b0392b7b793bec6f56c5d7162fca472ed00995d381
c5f3533849c988dc9812857c7a8e6359d82cf650955eec6d14661426e62bbde1
fc555917ce12a41761d6e21ef399d5be7dce2da3d15a05b2ce3fff10abcd77f9
80b3c8d9dcccf09f2cd697875d417ecfd90dc7ce3132ef10bc5d6f48510d19da
185a716f245f4951e997e91ca747ec2f52acf4fb0adf594bccd9c8acbfacf677
b996d0418d6d8ac7d8f9ce4d09d0eb1f0fd1b30d733499742a41a9c6930521b4
e5406c9136408ddbe90ec00c45b1291e3e847826ce1be6c39b77327d135e57c2
8ef455d1383249717a5d6215a98c176da08d5cf9f2d70f6d3ea24368b36b00c5
038849db19818c7136fe0a551b3f1b9ab11d51390ab2f4197f9f7c5ff16f6a8f
987d80fbc03ed5f7612a742982367ae5f354237968d23b2fe1cbe9440946497d
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
01e631c29a801330b7eb8f5904e171a8d47b044754153792955a459c25db112b
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
2f712c6b725905241f86c0a76963dc5053e59d0dbd1b0396dc2e88c3d94f54ff
1ec8e13c55c7d0114d1877cdce2e18be355218edce5ae2403ff928305799885b
5d19080b4f02064df1e03553721cb9269413ef21e5bee832d9dd5688f01db5e6
8de4312c046f3b3586dbf7a813d5678c2ad5dd319d476f4d64b403dc0d45f714
1e12346e4000bfaebac977089464afeb82b3729a90bb6ffd66dde49b2da297e2
8b903abd92011f515abe01bde91dbf27d2f8037e7712be038bf7bdad420b5e6e
ef522b08a1410eef91c4e03d3241eb012720d8e16ca363dd93a48c2b5c92df1f
f99d68393189fed84f6b667127e531a5f9efc410598335eb06a6b973462237e5
a5c29abda5dbd2006117b82fdadbb70f42354298b49019b73c36e31e8c6bdedb
7f4009e7a332b49ab49007e5cf74a87a6a7bf5a115a0acb621ff8657908ea2b3
81772deba6bfc78c34c1f83ecf47c84337e0b7592f96c6548b3e865a0a424eb3
0f0797053ff7a7b8e0bc5e75a5cd8e2eb91739101486374e4209c29a92fc2d66
7a9e36961ab5b2ab759ec2196d40618b1f43c5a04c40c01b31cfb4ea1adfc347
8f24522b05cd4032eff11b1f392146101cdc4ad4f65803c99cff824e4c425098
fc117f10fec938fc5983ad960142b3dafdc946dee592d13a37c6f21aee2618fc
5ae445a991d56393e514f68e235bf8e92b116fedc8cc6d17ae358b34f6873d09
347b852f5907744c87cb80e5564d3116724a895ed856265899ae011738868295
165005cb8423f38beba5461a10f3cf5fb69304013b5033463265c5457e48b76d
a8281f10a65d2066e0bb4d9089efbc567dedec223e6b77303223da17af9021dd
b90d30fabfd911bdf2b7d785dee57ffd346019b889601d1411df2872d7d020d5
e414dcedd89db359ee7d9efa34acd3524b578e627aa18fc627a0d2aee62569ee
1c2b963220cf175f77391b7fa2e2f27dc835144750b9c3c0c4c6ddb2e1cccc45
ebab7ddccea1d6b5a5d4e69bf2dccd2684fc00f5955ca5e6bc5bc51833247232
2e60e1e443fe9ccbc167bd093cbea48ed49743648f5c8df81c9d7356ac499194
d4bf3a107af69bbbc1ace1972e497847e2464ab843a32ca2074726f4d338cc82
2847c9264726b6c4abbcede6bfc40c2386e93e81a8cd968c19e5493e08851f1a
a60dc20a425f59e23a134fc5dc142605ef8663fb7a19829c9604c5b0a57e2f58
c4ec5232b93fdd3a9b66041c8c76944c56c024741c9210681884e3020436c72b
8a48ce8db35cc289949562cae156fce70a8e7f913b35515bce4cdc2741152b8b
e3c2797795813326d842d0d7973b5fbc8f0c797e920c96dc13c17d9705996e6d
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
773e56d43a64f8dc2f504591a154b045827841c9c352fcb0eb5e00ffb7d2494d
72cbefae43d92c6d12f7ca663d4fd6671b9496bfb2ec6f301cdd7baf6557a667
6191abc34c202d0c07426a07e18de87c7966bc66a5a986fccae897bb029431c7
8163272129040576b8ed3755405d3d54bafd4adb11815d16cf111414837b3341
acf357c833101ffeeaea46fc8db924fd2238fa60c93d0c16b9908d8b8daf605e
d288aeaba9ce6c45ea67888979e4810b2148c01c15c8312c95514112da7602b8
a4e306de360dd28b8d54760139d3b4b9fe5448d6c906ea3ff3bc54b3ab97ea27
0d12cb94f5a68cf9f6c968cfc79f79a7f33e5c4a8457c485e253b7a63c5c6651
7ca24db961bea0f4324c0e13110ab17aabc2da38f67311d2de046a263771858f
d41fe3fc605a799e6f95c52cc16d35a2f1bc03fd166187a1c6fd830f287e3518
f78935b754216fa45dccda11a77055e1ddfbf03caa112ad86ba7e48a16c385d9
10b85fb4905227bc1e37c8ebfcb317b188f9d93a761aa887977dae17c71de81f
0b3423499f53462afd426652f26d5a2cb90347cb3265bb35d7041727912670d2
4265f1052e30da8a8c0df275b96179f0ffdb01affc76d38169414575a8c0bd2c
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
320aa8c92e7c70266b35c8a5fc38ed069d68e6e1403b3ce56bab93fbd349d890
0c76624f247bc645309c46976f8f9a9b76d4c566df2fdd0c82058e98d07c80ca
887df6e244e8d356d468e6fd9a5712f918918b72fe18892f7a80b900dc89ea76
31684d56968063e799ddb7f470216b3b2114531e3a500439d5db90ac337800f0
99da41b6e12ed59550b34c28d2a84eae0a31c5395bd589230a368891d9053159
9a758275144859206b6f3149212ba72c51ead3549da162723bd7d28116fa522e
30788def3a21b46e13085a4144b9d9ecc316d68da8a2492cd7bfda1e9afd316b
9085dc203b9498343a992249942f8b6408180baa2bba58fb799c81a0d1855686
f5192d0f7603e198e0b3098e9204ab40d11958a9bc27d8477db41cd5350b6242
15f617e02521dc3ca65cdc5442d2e5d079a4bbf70d64b465b903d28fcda44103
60c02fe06b1245384055747b14c0c5af879c0973ff23c7701a45fd92372bf631
89f618ae5abb8b3dfd00db8271c120503dff7ae17af576f4169ba4036f4562d7
4b0172ec49e672667d9b9ce4ff5ea0365ce29118728adeda23e5c21e7e170ba6
1d4ec9427f7548ec009c707abcea1938109b5202fcb59712645ead4eca956a72
7a6d0f4a00f827cf525de3d0028ffc70e2114315bcddd1298a719ddf74eb98d6
54fb069a625c765bcad6274dee9288ca9b3ce6cdcbeacae37a1248edfc5bd89a
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables signed with stolen, revoked or invalid certificates |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | PE_Potentially_Signed_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.