MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cee833e9c596d9919c8c4b4b9aadf5dbbaed6bd64154c0d5644ae4c618e4b561. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cee833e9c596d9919c8c4b4b9aadf5dbbaed6bd64154c0d5644ae4c618e4b561
SHA3-384 hash: 23da2fe74f29aab3575579178fd19174aaa9f585339906f4c56b56b002ecc1d888139d09d35cc7a411712792d10ec540
SHA1 hash: 8792ec2e6ef59581164ba891a694ac8ba324be17
MD5 hash: bdd6a9a23bb7690f81bebd97c0b2dbf7
humanhash: uniform-arkansas-vegan-ceiling
File name:KHB Holland Company official document.rar
Download: download sample
Signature MassLogger
File size:642'999 bytes
First seen:2020-10-16 17:53:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:nKzfUvvMxfGlO/o1QlR6jPFKQI7DUc2KA/qVZLLtumMsbMGPHTki53kU:930fGlS4Ql8uDh3JxhM6PL/kU
TLSH 76D423B7D07086F97D23249B1A9E10FA9B0DEFB4806348312F2A98D650F5E6F51D7C86
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: tgc2018.com
Sending IP: 156.96.46.110
From: INFO THC2018 <info@tgc2018.com>
Reply-To: INFO THC2018 <thuyxnkr2019@gmail.com>
Subject: The 10th Turkmenistan International Gas Congress 2020
Attachment: KHB Holland Company official document.rar (contains "KHB Holland Company official document.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Zusy
Status:
Malicious
First seen:
2020-10-16 12:25:55 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar cee833e9c596d9919c8c4b4b9aadf5dbbaed6bd64154c0d5644ae4c618e4b561

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments