MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d091122abc815babad7afcc10be0fb5143f61018e1c1ff8a55a4232ac27a80d4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d091122abc815babad7afcc10be0fb5143f61018e1c1ff8a55a4232ac27a80d4
SHA3-384 hash: 95947b6d32fad12cd518e1efc409513aec347daa1263dda98225f193916971a100b2bac4b3ccced5a856e15984aac942
SHA1 hash: b5df9169fc2b97b3c1055f16ad0e3dc756b704b2
MD5 hash: 916656a1c29bd711dcd30788e12b2006
humanhash: purple-papa-uranus-berlin
File name:PO-NA0U909098899900 (1).zip
Download: download sample
Signature MassLogger
File size:653'899 bytes
First seen:2020-07-14 07:35:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:GYhGgofvOV4lJOnDY3ys4iCbFbWKmR6ZMfh+KVOmMjImvLVL2Rv4MvJN/kTxayfm:FhGgoF7YgXmtWKe60Nw/pBLYv4MBheal
TLSH A8D423F0BAFF816924B51AD8E5983F701570BBA728658A70CE1EDF1D3B518C98508B93
Reporter cocaman
Tags:MassLogger zip


Avatar
cocaman
Malicious email
From: "VIKAS C E" <deepakmehta@tirupatifoam.com >
Received: from tirupatifoam.com (unknown [185.222.57.163])
Date: 14 Jul 2020 00:31:43 -0700
Subject: Re:PO NO:AB1088
Attachment: PO-NA0U909098899900 (1).zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-07-14 07:37:04 UTC
File Type:
Binary (Archive)
Extracted files:
42
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip d091122abc815babad7afcc10be0fb5143f61018e1c1ff8a55a4232ac27a80d4

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
MassLogger

Comments