MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c701607a15dded41bccd054b3e2b84bccd855e4cab07e6523e113f03c5be920a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c701607a15dded41bccd054b3e2b84bccd855e4cab07e6523e113f03c5be920a
SHA3-384 hash: 8ac098139cfb7fbd2c5027c30e5a66bb2a4f651f9516bf4f5a997994bfd534c0ca6323935ccfe150cd3a9470fe4d9fff
SHA1 hash: 7521748215c62ee4d02eb2214c669a681c87f2c3
MD5 hash: 73be516149b9f256a7e92f45aea9e379
humanhash: red-batman-fanta-virginia
File name:PO556361TW.z
Download: download sample
Signature MassLogger
File size:334'611 bytes
First seen:2020-06-25 09:35:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ZJYN9Q8MvxOEkqUEn4VLWkWUaapZ5LUNAS5aqsExYcrAPyGI:ZJY3Q/kqr4VLfr6AmRePw
TLSH 7F6423F16C7FE14980D67A8FC02CA71674D37B0ECD80E6BA0A9960F19185B7F1DA1E94
Reporter abuse_ch
Tags:MassLogger z


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: omnisi.com.tw
Sending IP: 31.168.40.90
From: Alex Yang <alexyang@omnisi.com.tw>
Subject: 新命令 (NEW ORDER)
Attachment: PO556361TW.z (contains "PO#556361TW.exe")

MassLogger SMTP exfil server:
amazing-cool.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip c701607a15dded41bccd054b3e2b84bccd855e4cab07e6523e113f03c5be920a

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments