MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 de3f00b50a84b1b656d27ac821cfc6b156f6a02424fe13b02be8abc20a937d26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: de3f00b50a84b1b656d27ac821cfc6b156f6a02424fe13b02be8abc20a937d26
SHA3-384 hash: 43a9812737e8ce3ae3a71a81364e4869eeaddb395e5a293383130fb9e150cdb45b398eece828518a35726a7bccdf911f
SHA1 hash: a7cf110f2405c1b6b28353483e0556b5ee27319e
MD5 hash: 5f4c756d5f836fa6a9e97c819723ba69
humanhash: texas-pip-high-item
File name:POROÄŒILO NALOGE V MARIJI 2020.zip
Download: download sample
Signature MassLogger
File size:668'918 bytes
First seen:2020-06-03 11:32:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:NZxxqIgovdJR2ZiNXmviJLK6E0Nl4S0q864ur/wLH+rwYGwSLHHeJVtrl65p+gth:NZ7PBdP2Zir00b6oh/wrR1JLHH0Vhl6F
TLSH AEE423306EC0C49879B422F9D5FBE566E400829E6B9D31D8F2AD8F3135A5E3372D6706
Reporter abuse_ch
Tags:MassLogger zip


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: hosting12.ji-net.com
Sending IP: 203.130.149.250
From: Unimobil.SI <stamatakisdim65@gmail.com>
Subject: RE: [RFQ]: POROČILO NALOGE V MARIJI 2020
Attachment: POROÄŒILO NALOGE V MARIJI 2020.zip (contains "POROÄŒILO NALOGE V MARIJI 2020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 11:38:03 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

zip de3f00b50a84b1b656d27ac821cfc6b156f6a02424fe13b02be8abc20a937d26

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments