MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e65f3315bfd63c672678ea02318b8f675040201c8ee89c9d332a49509323d8ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: e65f3315bfd63c672678ea02318b8f675040201c8ee89c9d332a49509323d8ab
SHA3-384 hash: 7d473284494ba79bc248c72daae052de5824149b67664ab0b2145a8320848fe77229b08d2f4184dda5932147a5de432b
SHA1 hash: 846e9cf2edf187f079f54ee5ca8ff2bef1aa1e06
MD5 hash: ac0a78d1471c27e932f5d609b9d06f80
humanhash: pasta-two-football-seventeen
File name:ORDER LIST TBM INFOTECH Dubai.rar
Download: download sample
Signature MassLogger
File size:17'734 bytes
First seen:2020-10-13 05:45:30 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:5Czmkci/gk1ykIAnyoQAObZBMA4zTcC42INLisJIgfOJSihYW8vAvBxkE:5gPc/9kItgAeYC42INjLelyFAvgE
TLSH F882D00FCA0F8EDE6675D468952FBFA38D10B558EF1153F299952243F169889C1C8E31
Reporter abuse_ch
Tags:Endurance MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: 162-241-204-248.unifiedlayer.com
Sending IP: 162.241.204.248
From: TBM INFOTECH Dubai.<info@emexleathersuppies.solutions>
Subject: RFQ FROM TBM INFOTECH Dubai.
Attachment: ORDER LIST TBM INFOTECH Dubai.rar (contains "ORDER LIST TBM INFOTECH Dubai..exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar e65f3315bfd63c672678ea02318b8f675040201c8ee89c9d332a49509323d8ab

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments