MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 c2ef3750476176f2696e08a6e733c3c39df6cc239aed61cad77b34250dd4f69f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 4
| SHA256 hash: | c2ef3750476176f2696e08a6e733c3c39df6cc239aed61cad77b34250dd4f69f |
|---|---|
| SHA3-384 hash: | f5b49f9263e53528f0ad1c432ca7cc621168c374d4ae61879b87bdf15a2656aee0d064c2a3b857e319d9abdfea6fb889 |
| SHA1 hash: | 19d94fbfe40d5821138498e3b34527f65ce739e6 |
| MD5 hash: | 2ef1374f771848bab18b1f2fee406b7f |
| humanhash: | uranus-louisiana-hamper-august |
| File name: | QWBN6438.rar |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 913'235 bytes |
| First seen: | 2020-12-05 15:25:29 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 24576:bZzc9zldQDOtaSh45JGk5UM8/+ApT1tD8zBzxHF5BzU:9zc9zlGycGk5UM8lTPgtlHF5+ |
| TLSH | DF15334F58D4B9085B398ED1061FDFF27C89F59FDBD082860EE2C78950021B767AB269 |
| Reporter | |
| Tags: | HostGator MassLogger rar |
abuse_ch
Malspam distributing MassLogger:HELO: gateway23.websitewelcome.com
Sending IP: 192.185.49.218
From: Mr. Sales <info@bahraincontractors.net>
Subject: Attached T/T copy for payment.
Attachment: QWBN6438.rar (contains "kVqQhg9evpzeNYL.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
345
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2020-12-05 15:26:12 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
1/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
MassLogger
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.