MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e13e69844f408a554bd0b8cac5fb83501d1873d62247f27d71c4209daef6ebb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e13e69844f408a554bd0b8cac5fb83501d1873d62247f27d71c4209daef6ebb3
SHA3-384 hash: f900e2863b162faab47d8966b8ff41d502e40afed2a5f50bd7c17947d0f9800e8306f9379272253875798501f09003a8
SHA1 hash: bc0c1094b790f0b8e48fd9816c5a12d8d2cf5c62
MD5 hash: b837a926e7b2f95b1567b75471651c30
humanhash: twelve-alpha-florida-arizona
File name:INQUIRY_RAW MATERIALS.rar
Download: download sample
Signature MassLogger
File size:801'805 bytes
First seen:2020-06-15 05:45:16 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:XzQvr8CA9Pr4XvJzExcO4zjRhAR+vOfgLjF4RlBF3U9irqw:XzQLA9PrkJENoRSQs4wlDd
TLSH D20533E13F46160019C3A67D3DACA926C3B437844F3F61AA5CA263D1CFECE635A495C9
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: rhino.lk
Sending IP: 37.49.224.135
From: Thilina Jayasinghe - (Senior PO) <thilina.jayasinghe@rhino.lk>
Subject: Re: Inquiry for Raw Materials
Attachment: INQUIRY_RAW MATERIALS.rar (contains "INQUIRY_RAW MATERIALS.exe")

MassLogger SMTP exfil server:
mail.privateemail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-15 05:47:03 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar e13e69844f408a554bd0b8cac5fb83501d1873d62247f27d71c4209daef6ebb3

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments