MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c124246e9c0a479da29aca99ff398a2dcd2e3d75f5ece191e36476a402ed1aa4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c124246e9c0a479da29aca99ff398a2dcd2e3d75f5ece191e36476a402ed1aa4
SHA3-384 hash: 03101f57bb239320da963584fe0abdcc238c11ad0e2146780781a092576567387dd8f44f6893b0de822dba535f80280b
SHA1 hash: cb3834b41da053fd05fb8a08a5f26a35d597f918
MD5 hash: 8a88d907878db971ed21caec536afb5f
humanhash: twenty-artist-seven-alpha
File name:GKUN364.rar
Download: download sample
Signature MassLogger
File size:982'360 bytes
First seen:2020-10-13 12:27:01 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:etkeBp/P01xjxn2ast2rLZ6PQqeeCSOQW1AVjdF:exbcx2aIPQ+v5EAVn
TLSH BA25331BA91B403AB2C68D02D3F197E8EBC62DB817E57167F56C8107A5D012E7D3E9C8
Reporter abuse_ch
Tags:MassLogger rar Yahoo


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: sonic304-19.consmr.mail.sg3.yahoo.com
Sending IP: 106.10.242.209
From: MASHA TRADEING <masha_tradeing@yahoo.com.sg>
Subject: : Fwd: Wire Transfer Payment
Attachment: GKUN364.rar (contains "yp3E2QR8CeZp9Au.exe")

MassLogger SMTP exfil server:
smtp.yandex.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar c124246e9c0a479da29aca99ff398a2dcd2e3d75f5ece191e36476a402ed1aa4

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments