MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0aa6c2f673df8b8a98d3df001a392914384b5adf043652f11b123a6a2c49237. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e0aa6c2f673df8b8a98d3df001a392914384b5adf043652f11b123a6a2c49237
SHA3-384 hash: e8ce17399e63b6bd71f376d1b4ec1dd8f8311150974d8d5e1e6563bacf2400192a66633ee7f61a82e73b3e4a5f2105e3
SHA1 hash: d777ba76921d72af7940fd850ecbbd0744556d14
MD5 hash: 9cb284b0139adf5791a3333a21e62a66
humanhash: beer-fix-chicken-undress
File name:Product_List.rar
Download: download sample
Signature MassLogger
File size:794'588 bytes
First seen:2020-06-17 05:39:00 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:99r1cylZ0w20jTe0JVLt05V76aXIJkplxhXHsOn6n8BYzNrBcCiGX9Yc7:RZZ0B0Jtq596stHB680GCl9F7
TLSH DDF42307DE50E1A23F4982CE8CA38F1EFD5582BCFC7A3F841917794A7744A465AE3601
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: nantekimya.com
Sending IP: 37.49.224.134
From: Huseyin KURT <destek@nantekimya.com>
Subject: Price Requests
Attachment: Product_List.rar (contains "Product_List.exe")

MassLogger SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-17 05:40:12 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar e0aa6c2f673df8b8a98d3df001a392914384b5adf043652f11b123a6a2c49237

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments