MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 17


Intelligence 17 IOCs YARA 19 File information Comments

SHA256 hash: c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28
SHA3-384 hash: e697cc04bd4a2c7b0776b7e9d655645efd4579d07840c262416d64293a5eefbfef2d085c7238aa0a526dde57519b352a
SHA1 hash: 5c0ac1dfb986c836637370777161b2c1e07fbfc6
MD5 hash: 8a643af5f13fd74b2fc3ac9686f51860
humanhash: bulldog-winner-california-football
File name:DHL Air Waybill no 6979374150.exe
Download: download sample
Signature MassLogger
File size:577'544 bytes
First seen:2025-04-18 16:17:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'658 x AgentTesla, 19'469 x Formbook, 12'208 x SnakeKeylogger)
ssdeep 12288:X1djgCRxKYIeYRYOpsaEVGjb9aUUSmaOWzConrQ/gcYxkR:X3IeYBpeG1aUKKdnrQ/JYs
Threatray 721 similar samples on MalwareBazaar
TLSH T19CC4E00022899A03C9961BB45962C1712BFBAE49A9E2F7365FED3FFB74627403107357
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10522/11/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 014165132b454105 (2 x MassLogger, 1 x Formbook)
Reporter abuse_ch
Tags:DHL exe MassLogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
419
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
DHL Air Waybill no 6979374150.exe
Verdict:
Malicious activity
Analysis date:
2025-04-18 16:43:33 UTC
Tags:
netreactor snake keylogger evasion stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
virus krypt spam msil
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Launching a process
Restart of the analyzed sample
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
entropy expired-cert invalid-signature masquerade obfuscated packed packed packer_detected signed vbnet
Result
Threat name:
MSIL Logger, MassLogger RAT
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Adds a directory exclusion to Windows Defender
Contains functionality to log keystrokes (.Net Source)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Scheduled temp file as task from temp location
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected MassLogger RAT
Yara detected MSIL Logger
Yara detected Telegram RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1668520 Sample: DHL Air Waybill no 6979374150.exe Startdate: 18/04/2025 Architecture: WINDOWS Score: 100 55 reallyfreegeoip.org 2->55 57 mail.cl-logistics.vn 2->57 59 2 other IPs or domains 2->59 69 Found malware configuration 2->69 71 Malicious sample detected (through community Yara rule) 2->71 73 Sigma detected: Scheduled temp file as task from temp location 2->73 77 13 other signatures 2->77 8 DHL Air Waybill no 6979374150.exe 7 2->8         started        12 UWThGyU.exe 5 2->12         started        14 svchost.exe 2->14         started        signatures3 75 Tries to detect the country of the analysis system (by using the IP) 55->75 process4 dnsIp5 41 C:\Users\user\AppData\Roaming\UWThGyU.exe, PE32 8->41 dropped 43 C:\Users\user\...\UWThGyU.exe:Zone.Identifier, ASCII 8->43 dropped 45 C:\Users\user\AppData\Local\Temp\tmp4A.tmp, XML 8->45 dropped 47 C:\...\DHL Air Waybill no 6979374150.exe.log, ASCII 8->47 dropped 79 Adds a directory exclusion to Windows Defender 8->79 81 Injects a PE file into a foreign processes 8->81 17 DHL Air Waybill no 6979374150.exe 15 2 8->17         started        21 powershell.exe 23 8->21         started        23 powershell.exe 23 8->23         started        25 schtasks.exe 1 8->25         started        83 Multi AV Scanner detection for dropped file 12->83 27 UWThGyU.exe 12->27         started        29 schtasks.exe 12->29         started        61 127.0.0.1 unknown unknown 14->61 file6 signatures7 process8 dnsIp9 49 mail.cl-logistics.vn 103.126.160.162, 49691, 49692, 587 ONEBIM-AS-VNOnebimVietnamLimitedCompanyVN Viet Nam 17->49 51 checkip.dyndns.com 158.101.44.242, 49684, 49685, 80 ORACLE-BMC-31898US United States 17->51 53 reallyfreegeoip.org 104.21.80.1, 443, 49686, 49687 CLOUDFLARENETUS United States 17->53 63 Loading BitLocker PowerShell Module 21->63 31 conhost.exe 21->31         started        33 WmiPrvSE.exe 21->33         started        35 conhost.exe 23->35         started        37 conhost.exe 25->37         started        65 Tries to steal Mail credentials (via file / registry access) 27->65 67 Tries to harvest and steal browser information (history, passwords, etc) 27->67 39 conhost.exe 29->39         started        signatures10 process11
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2025-04-18 16:18:20 UTC
File Type:
PE (.Net Exe)
Extracted files:
11
AV detection:
21 of 24 (87.50%)
Threat level:
  5/5
Result
Malware family:
masslogger
Score:
  10/10
Tags:
family:masslogger collection discovery execution spyware stealer
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
MassLogger
Masslogger family
Verdict:
Malicious
Tags:
404keylogger
YARA:
n/a
Unpacked files
SH256 hash:
c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28
MD5 hash:
8a643af5f13fd74b2fc3ac9686f51860
SHA1 hash:
5c0ac1dfb986c836637370777161b2c1e07fbfc6
SH256 hash:
fd20de780e122711cf3c564e4d271ee2336d7dc7b0c900bc1f8f467bd9ad7e61
MD5 hash:
8a95c3f43b3e5c7871870d44d990c03f
SHA1 hash:
0991061b3a1b9016d0d89b21a2698002c307a548
Detections:
win_404keylogger_g1 win_masslogger_w0 MAL_Envrial_Jan18_1 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
SH256 hash:
faef94e074289a13422cd82a77ea323da9b60bd4b9137cd171836db05078ea75
MD5 hash:
3fdaaf8d2a342674650c626a747da024
SHA1 hash:
f8576ff53bd70a6fab5769e92481184334396fa4
Detections:
win_404keylogger_g1 win_masslogger_w0 MAL_Envrial_Jan18_1 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
SH256 hash:
4f90dd2abcc43b2dc177cc70468da00a7e64bb555d4dde54220e9ae6d0321744
MD5 hash:
4b1150aac799f8c82c3308df0f4069c5
SHA1 hash:
03a197a899b6f206be28f04d36dcff2bfc020577
Detections:
SUSP_OBF_NET_ConfuserEx_Name_Pattern_Jan24 SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
6151887cca2fbc0c327b5ec675783def1f18fc207c83dd3437c0ca586dac21bc
MD5 hash:
92adcfb9c4379ff8ef129b0e8d402587
SHA1 hash:
04ef2d22bb26c3b350d2302eb65b0d3033476e8d
SH256 hash:
099e9ede0bc66000057eb440b14859b2031023261d3497c5aee1060513539b17
MD5 hash:
ee8c6d32ecc312a6651fef4c50c7f6f9
SHA1 hash:
49d7575008799429fb94426caaee4d51023e64c1
SH256 hash:
6ade419480e409a8757099d12995004ffdcbaa6c1899f9f2502e7ef8cc937b83
MD5 hash:
4bbb5bdde20e29c680c41488934f0d05
SHA1 hash:
52d04e54f63d0e8e9a69fccd1757ae724829b71f
SH256 hash:
31bc97a1ab065dd497e772032a542190b899ea5b995edebe86595d7d6dfe06ad
MD5 hash:
533b08152584b64a607845c10c751ff8
SHA1 hash:
6486d16b037ac1a3b7241c554f17df34a707511e
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
Parent samples :
bd11383a61346123c23e3959b9f9e2f85ff23f9b09a88256f4c67c26356a980a
3489a2eab1c57d0eee2ce6e5773e1f4f53ee6e5d8963e0099efc7e190d0c2f1c
e6fe2241c57847a4911e325b6d3692839f9033de0c99ddeabd47e8d62022bcd1
faac3d9161a1d539ec42986280eeab6246b71c427fa176a239562c110448a1c1
074efb70a49088638d0e62cc3637a75627afe9286c3f2d024e78ea9f247582fe
23808b7d7764dc5d702974b63f7b15c92d86e0ca95826edb47b2f919d911b9c8
6036a28c74493ce0e6d87a468959a047011d2e6cf63807d9a3d154b8642d7e65
be838fc4e67ed12838f4d0ec554524d54e80a03a3949ced4edfb958edbcb24b8
4867fd993605221960bb0289477ed3a14727ed81cc14b8da8b61e3f509d097f5
37da80758e0acd6993e9a2639927c5bcbf8388526fa93168a9b70f6619775df9
c06298e32597bfdf3374174b8f458169df5d561280f5aa11fd25868c67a5de9f
a90bca8c1f6a63cc34a896eb3883428fab6fb6b4aca385ac917fdafcdbf9e774
048ae81730730b45b67054c6ca4e83d727c07b14568397bc95ef51e4825e830d
ea8cce203873c762292f08d1d461a3f38521f1e77bc175dd68b4fef76ceabd19
bda5884e1a65b59d74d3366608a4841111d43d0b6a865879736f5179bac1bcf3
fa1cfaafe2029ee02035b899a389916cb02bac4270d3f438be0a5013f170e420
f2414faf44fac2135ccce1d5fe5c3a53ec3fcde7ad295e2e112af373b02da086
03a317048a5778933751cbf631e08c5b870ec2da45d74466c53f460a603d7d42
4d59b35375d85ca3dd06c76cedea67009a37075e179d0ae192b9412b24bec974
54f50cdad3e5039d3207566e1b9de6e16913993ba2aa711e6f91a68e093ed9c4
b9ee87f239e3ee4599d666b1b755f97ab4c2ab45507654ec1485f9d60af710ca
c6424a8d5558035680e043348443092f2ad0295be323d2848f6509639990ea28
278854f2430457153ca438c78d14f2469083281da9ec3baebad93d4dd7a3c125
1e98340b6b95bf8c7f96f0b3825473f914d71f78dd2a3032f1f8c3b78c118223
8ef48c6c52f5fed10b8d7c572da9d657ba1fb813a04356de5a47055e9b1250ef
9c100d322eee0b94c9d996c7bc1167df02a820d34dd4b5ee30748d331b064595
c7de64db20145557f5070412a4e15d4d2a00487974e8fce0f4bc3ee42999bd04
5b97cd88bfb20b5d92d426072bc581d159fea064159872e983805bd2c225e64c
ff5bccafd98ba9bd46b459881d752902794630c891dd98764fc1b51cb25a1aed
800a4bab620b5a0c3e184b76cd1a345d5b74b7754fd6aa10a37742e801c5d850
b91da8b8d9a3a5da385a0bde839b80d16824f485746b75597e9236a96d7b2445
3bed682a9298367059c63e05f0b565dbad9f5959302f239c00a92eb3aeb16d67
a7ae95af3a74e706c7a3370b351ba6070b7470e5b6fae98b59fc2612d1e4376e
3701cf2e0022ea59c5f97f083a6f4d975cd0f8f047b3ed0e2c9b29c462605ac8
07a74041ab09d6e30042a163e518da8c70f644924d576a268c981baad87a19ae
699abf03b319292d82d86e3669e6e0e59ed5d704064c56212dbcbde4a8d8fadd
8b3c3e6d8c540773529da82ad7c28265d6a5462e96d1f07a7781dd76c6004ac5
e0ec24c22840b9435a7fcba35fcc9fc13b371abea00ead5ef60ec9f0893630b3
013ac70a93289c1dd9d84ff03a4d4ffc6256f185b098c92ee8dda039201ef8ec
51fde361f93dc3702ed13354d064da8422188f3e1b06d9c9b04951da07d89cb8
dc4e9ca482f2b9e15b04d70b2be7ecb6ec63a40e83da756503cbb1b9fbe023c1
5f8549af42d110a594441941f439b1a7c1d58ec75cf7acf9c9bdfcea75dadedd
SH256 hash:
eed6d758e6702d3b9fc3b15760d2dcba7f88a3eebd8b3d07b997818fd5555d25
MD5 hash:
ee8411229c625218b2adba7dfc725129
SHA1 hash:
736772222acded0bded7e2cb748c9bc07ac5fc9e
Detections:
win_404keylogger_g1 win_masslogger_w0 MAL_Envrial_Jan18_1 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
SH256 hash:
f14d39867c8e4c94e36e483dc55ac07ab210d11f0715b9664cc231c1184e3e69
MD5 hash:
2551fd57b50bbd5ffdee7e72c486e5ed
SHA1 hash:
8487f454dc73151cdebce6bfee8eb60a031a4169
Detections:
SUSP_OBF_NET_Reactor_Indicators_Jan24
SH256 hash:
faf7835876a18c44d716116ea4a74cdc76c608d8b57854fc770fc51add695f37
MD5 hash:
38ae5cad2376f33a7e38d4d375893e12
SHA1 hash:
934bc224376bbe0ec027a01c65835d763f0daf17
SH256 hash:
1a344b32823f637178b6285661a748b06c0cc92b9426b9b0c242aa6723c69b1c
MD5 hash:
e58e4914139267ff75fe2e25bc98d104
SHA1 hash:
ad4afbc14de62391d9d64d8d48cc5f597d5eb2fd
SH256 hash:
fbc68d0c6e9a56a4c7937e802bac7f63999411921f540361b35ccd9171af9ba6
MD5 hash:
79eca249d6612459b9bab3dda32dfc29
SHA1 hash:
c41e0c92b64adbea4c66e17724e8a145d8fecb3d
Malware family:
PrivateLogger
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:crime_snake_keylogger
Author:Rony (r0ny_123)
Description:Detects Snake keylogger payload
Rule name:INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438
Author:ditekSHen
Description:Detects executables signed with stolen, revoked or invalid certificates
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_TelegramChatBot
Author:ditekSHen
Description:Detects executables using Telegram Chat Bot
Rule name:MAL_Envrial_Jan18_1
Author:Florian Roth (Nextron Systems)
Description:Detects Encrial credential stealer malware
Reference:https://twitter.com/malwrhunterteam/status/953313514629853184
Rule name:MAL_Envrial_Jan18_1_RID2D8C
Author:Florian Roth
Description:Detects Encrial credential stealer malware
Reference:https://twitter.com/malwrhunterteam/status/953313514629853184
Rule name:masslogger_gcch
Author:govcert_ch
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_imphash
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API
Rule name:Windows_Trojan_SnakeKeylogger_af3faa65
Author:Elastic Security
Rule name:win_masslogger_w0
Author:govcert_ch

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments