MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ccbdec866c4dc5272bf35d9e08186c71031cfc63d37e45d96a35d69cdfb5dfe6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 20
| SHA256 hash: | ccbdec866c4dc5272bf35d9e08186c71031cfc63d37e45d96a35d69cdfb5dfe6 |
|---|---|
| SHA3-384 hash: | c724bd95cb2735a1897eb8a446cb81f00970e9adaed03d091ff0a992a0472bde8138dc3cb8b68c7c8b2df951f0398f06 |
| SHA1 hash: | 10f907eb4dbcaab348edc1953f4a3baa482cfb4f |
| MD5 hash: | 140265f9acc7a7b5d70619f54846112c |
| humanhash: | table-black-pluto-fish |
| File name: | OFFER CAPEX E2652 xls.pif |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 1'015'808 bytes |
| First seen: | 2026-05-19 18:16:33 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'003 x AgentTesla, 19'911 x Formbook, 12'332 x SnakeKeylogger) |
| ssdeep | 12288:DvIfO70YT9uC03AziAHVWXPyaapTw6g9hwLNi5xBheJQck4Npm7ihItAHkBCpOwB:j70YT9uClvHAXP8p8dX/jB4JxQ2EC0P |
| Threatray | 160 similar samples on MalwareBazaar |
| TLSH | T15D25126C6A06E503CAA12B396EB2F1B4075D1CDDEA01D347DFE9BDEBBA77A041C00155 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
2b1709a9c749ff0e6bca3643813dd090ac492a20104666259f65939d5e0c40b0
9d5c8e9c41ff08b0a3be489ac1ef0f014f2749ad0e3217af2e0665c514a072fc
e463f87a0c098ff8bcbc4c262e9eddf3dea51148d2ba9d12c64addb21e2ff978
ccbdec866c4dc5272bf35d9e08186c71031cfc63d37e45d96a35d69cdfb5dfe6
3b80f1666e8725435546d010c6f775ec852dd7691618236563e1bed1043da625
733c3e1e510fe841346e63a3728ec2d195951ef1b70992ee1de55e42f353a10c
82e9f638f4235a110559bbb2e9d83c4f72c23040799c80fde7e9503cfe66aa6e
6a2cefdd2b5810aef5388f4b23392847ae4abe6d4142ea7145e0afd04c00fcab
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.