MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bcc12f8e3b23886188da3027bc2954d55ca27280d5db7d8cf9e3d1028d2941a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bcc12f8e3b23886188da3027bc2954d55ca27280d5db7d8cf9e3d1028d2941a0
SHA3-384 hash: 54152bf85182a24661167451c4472440db02287e5ea33c9b6ad74dac9a05bb61e8286917daa4adbbed75adb39b55c4b1
SHA1 hash: 629a745ad7309d956c9f8d2f606a8fcbb8ff588f
MD5 hash: 30468faa6799f42e9ca723d4a1489020
humanhash: crazy-fruit-whiskey-mirror
File name:Our New Order No. 1557117. Dated.05.08.2020.img
Download: download sample
Signature MassLogger
File size:1'245'184 bytes
First seen:2020-08-05 11:47:27 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:HRm9cntWZhPBCTPCB0rQIVY1u3ai/iiPq:xmiI3g5QGq8iiP
TLSH 5B45AD2136D61102EB7D4B3207DBCE70373546A3ABB1821D7F2EA738DB109961869D6F
Reporter abuse_ch
Tags:img MassLogger


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: rogri.ro
Sending IP: 176.9.80.3
From: geanina.alexandru@rogri.ro
Subject: Urgent New Order No. 1557117. Dated.05.08.2020
Attachment: Our New Order No. 1557117. Dated.05.08.2020.img (contains "Our New Order dated.......exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-05 11:49:06 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

img bcc12f8e3b23886188da3027bc2954d55ca27280d5db7d8cf9e3d1028d2941a0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments