MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 d8aebda89bb5717256e78b44dd9e9ef54179d3590f7a6125da452e877c083c48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 8
| SHA256 hash: | d8aebda89bb5717256e78b44dd9e9ef54179d3590f7a6125da452e877c083c48 |
|---|---|
| SHA3-384 hash: | 634610df2457f68f606af1710808cf3942d26082ae360e7e3bab08101a80a0de36bee090b5a38b548912443898c979f9 |
| SHA1 hash: | 3d65197d3e91fe758f993afe9502c2079bb2dc14 |
| MD5 hash: | 256f8955f0533c15eea9cbe9711a417a |
| humanhash: | foxtrot-green-march-early |
| File name: | doc20200930_6650008538_87387743.exe |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 933'376 bytes |
| First seen: | 2020-10-07 10:44:22 UTC |
| Last seen: | 2020-10-07 12:24:19 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 24576:YJ7RwcXupvM8fjg5CyA3JF/2DeYHwkYEQ4:O7/uptgsflu377Q |
| Threatray | 260 similar samples on MalwareBazaar |
| TLSH | B215F1AC355075EFC85BCD768A686C60E6216877570BD20B901326ED9E0EACBCF152F3 |
| Reporter | |
| Tags: | exe MassLogger |
abuse_ch
Malspam distributing MassLogger:HELO: bdpint.com
Sending IP: 156.96.62.59
From: Basak Kurt <basak.kurt@bdpint.com>
Reply-To: Basak Kurt <javedsulirna.business@gmail.com>
Subject: PO#SM0006045 EBAT ONAYI
Attachment: doc20200930_6650008538_87387743.r00 (contains "doc20200930_6650008538_87387743.exe")
MassLogger SMTP exfil server:
smtp.yandex.com:587
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
e576e88eba32ee86d13bd2d490595abe936b78955d193d5523f0f5ad23c5ec9c
08c7131cac4c6c62004d8b2e3ce0b85d1b35e7325f753a865206814cd87ecdf4
e1392a3d2fb4e8f4642bac6694948fc8ceeb970fc5acce7c04b4d97352122be8
25f48722bf24e935d7bdca104b416f87424ced29dfec2fbebc817725f09af5f1
f8776b137f7c04fd40d7b3739011710eedbfe4472e013904300ca6ebc93a3c37
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | masslogger_gcch |
|---|---|
| Author: | govcert_ch |
| Rule name: | win_masslogger_w0 |
|---|---|
| Author: | govcert_ch |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.