MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b81cee551b60132814d85842ecc54cc65b19d230378d942912112e1fd4b3da29. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b81cee551b60132814d85842ecc54cc65b19d230378d942912112e1fd4b3da29
SHA3-384 hash: 7f36e121ae80bbe70e28f3467dce33025f0ef092f3de543ab482a0ce7e9dd5da3aec505576eb4ae0811c69f79a950232
SHA1 hash: 9cd472e445394e63290048c7ecca8f0e1272ad3f
MD5 hash: 96d18cb4f42e868674af3be1a44094f9
humanhash: hotel-lake-oregon-oranges
File name:RFQ- 14000118901.rar
Download: download sample
Signature MassLogger
File size:702'838 bytes
First seen:2020-07-16 06:27:19 UTC
Last seen:2020-07-19 10:49:34 UTC
File type: rar
MIME type:application/x-rar
ssdeep 12288:rKeE0WcXVEyPurYWu37iCAxLSeTIiHf7AolnmNGA5ofAT5gWEsyLab:r9WYlPurYWMOCeSiIiUol2SAl9Escq
TLSH 5CE4332F01BEBC7765EC85F6C7190EB35BE148E8577E44BCA9ED0DAD87288834461E60
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

From: Mohammed Savad <mohammed.savad@hailcement.com>
Subject: RE: RFQ- 14000118901
Attachment: RFQ- 14000118901.rar (contains "RFQ- 14000118901.exe")

MassLogger SMTP exfil server:
mail.itdone.cz:587

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-07-16 06:29:05 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar b81cee551b60132814d85842ecc54cc65b19d230378d942912112e1fd4b3da29

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments