MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc8b787d8146b1014359b22bcac287d8b23f62f77c186ee5ac3fa744b4a7842f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc8b787d8146b1014359b22bcac287d8b23f62f77c186ee5ac3fa744b4a7842f
SHA3-384 hash: 940d1214a4f7921e51cf4d4e1ec43dda519917f0469304899a61bc250164193ceb43f89c9d552154424af6504b9c1ab4
SHA1 hash: 48bfd5435bf2b318e00666f886b296a7bc6503a7
MD5 hash: 81e6cb12d1d47f5d9765540287b0990e
humanhash: charlie-steak-winter-six
File name:Ziraat Ba..esaji pdf.rar
Download: download sample
Signature MassLogger
File size:1'032'517 bytes
First seen:2020-10-21 08:56:09 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:9ZqiecvuWQEv324M33y8IPjaKXEtDAmXa4+VdgScZ:9Zqi7vuW/1nbamE8dA
TLSH AE2523325E9909ABB794DD502C186DC88ACE2CF26131FE9D0F99662E2098D74F94D0CF
Reporter abuse_ch
Tags:geo MassLogger rar TUR ZiraatBank


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: srv1.demspor.com
Sending IP: 31.169.94.221
From: ZIRAAT BANKASIil <ziraatbank@ileti.ziraatbank.com.tr>
Reply-To: ZIRAAT BANKASIi <ziraatbank@ileti.ziraatbank.com.tr>
Subject: 4000, EUR Swift Bildirimi
Attachment: Ziraat Ba..esaji pdf.rar (contains "uA8X4cCaArMOkx7.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-21 06:27:42 UTC
AV detection:
4 of 48 (8.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar dc8b787d8146b1014359b22bcac287d8b23f62f77c186ee5ac3fa744b4a7842f

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments