MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b74d77c359b3eea168c342dda78f18f8afaf6379763ca8221e91ebdf1673d4f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b74d77c359b3eea168c342dda78f18f8afaf6379763ca8221e91ebdf1673d4f0
SHA3-384 hash: 2a1cf2fed4b0e5175df80e7196a78c69d40b5c8cf6a411686c8940fd86084670853bb3330dc40e6941495b2997c4210a
SHA1 hash: 5fad54b9e77eff9fbf5500aa89dd304c3b77f2d3
MD5 hash: c813b9a018b0607afcf92db78c837824
humanhash: venus-yankee-ten-wyoming
File name:file.dll
Download: download sample
Signature MassLogger
File size:395'776 bytes
First seen:2020-11-03 21:15:08 UTC
Last seen:2020-11-03 22:48:59 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash dae02f32a21e03ce65412f6e56942daa (123 x YellowCockatoo, 60 x CobaltStrike, 44 x JanelaRAT)
ssdeep 6144:NNuX02PYHop0qZHf7dm3ybpoJaFPhX0jQbw13baUO57af+87OqJiYv4XGwIHyBss:NNukU+U5m8pldhXsQbsraUNiYbfHyB3
Threatray 79 similar samples on MalwareBazaar
TLSH EC842203F78FAB24C11CAB79E2A012050776E7C52393EB4D398FA21A1D537C74E46E68
Reporter James_inthe_box
Tags:dll MassLogger

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
.NET source code references suspicious native API functions
Machine Learning detection for sample
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Behaviour
Behavior Graph:
Threat name:
ByteCode-MSIL.Trojan.DarkLoader
Status:
Malicious
First seen:
2020-11-03 21:14:51 UTC
File Type:
PE (.Net Dll)
Extracted files:
2
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
b74d77c359b3eea168c342dda78f18f8afaf6379763ca8221e91ebdf1673d4f0
MD5 hash:
c813b9a018b0607afcf92db78c837824
SHA1 hash:
5fad54b9e77eff9fbf5500aa89dd304c3b77f2d3
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments