MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 deb8fb9bc1c4e6caa98686aac69426e9d05f24a224fdcaa481505edbcc4205db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: deb8fb9bc1c4e6caa98686aac69426e9d05f24a224fdcaa481505edbcc4205db
SHA3-384 hash: 793ef071997267c81576099eb0e6b5f72d97014689191e482a5054b5e177781e21129e8714ffbd1a035539795d1f5ad3
SHA1 hash: d64be57928319c5844ffcd76ca067f04108256b1
MD5 hash: 7fa71fd4531ff0d54982a3858ee2a3f8
humanhash: dakota-north-sad-alpha
File name:PO29572210.gz
Download: download sample
Signature MassLogger
File size:813'566 bytes
First seen:2020-08-05 11:41:13 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 24576:EarSLpAy1NwqUTbiznsL55qhwNOxyLE/vxN:EdpAy/znWNOwE/ZN
TLSH 69052359104E4A98B6A3577BE6C58C56F59718603EB7C3F0384F1A21D04F3464AA3EBF
Reporter abuse_ch
Tags:gz MassLogger


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail9.kergyoilfleld.com
Sending IP: 161.35.235.26
From: Saleem MD<tawee.ku@panuspoultry.co.th>
Subject: RE: RFQ
Attachment: PO29572210.gz (contains "PO29572210.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-05 11:43:07 UTC
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

gz deb8fb9bc1c4e6caa98686aac69426e9d05f24a224fdcaa481505edbcc4205db

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments