MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c2ef3750476176f2696e08a6e733c3c39df6cc239aed61cad77b34250dd4f69f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c2ef3750476176f2696e08a6e733c3c39df6cc239aed61cad77b34250dd4f69f
SHA3-384 hash: f5b49f9263e53528f0ad1c432ca7cc621168c374d4ae61879b87bdf15a2656aee0d064c2a3b857e319d9abdfea6fb889
SHA1 hash: 19d94fbfe40d5821138498e3b34527f65ce739e6
MD5 hash: 2ef1374f771848bab18b1f2fee406b7f
humanhash: uranus-louisiana-hamper-august
File name:QWBN6438.rar
Download: download sample
Signature MassLogger
File size:913'235 bytes
First seen:2020-12-05 15:25:29 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:bZzc9zldQDOtaSh45JGk5UM8/+ApT1tD8zBzxHF5BzU:9zc9zlGycGk5UM8lTPgtlHF5+
TLSH DF15334F58D4B9085B398ED1061FDFF27C89F59FDBD082860EE2C78950021B767AB269
Reporter abuse_ch
Tags:HostGator MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: gateway23.websitewelcome.com
Sending IP: 192.185.49.218
From: Mr. Sales <info@bahraincontractors.net>
Subject: Attached T/T copy for payment.
Attachment: QWBN6438.rar (contains "kVqQhg9evpzeNYL.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
345
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Packed.Generic
Status:
Suspicious
First seen:
2020-12-05 15:26:12 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar c2ef3750476176f2696e08a6e733c3c39df6cc239aed61cad77b34250dd4f69f

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments