MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee89c86eed2f5114c759a47aa7f49a32af7c2eacf3299c6e2b1b08f54cdb8d9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ee89c86eed2f5114c759a47aa7f49a32af7c2eacf3299c6e2b1b08f54cdb8d9c
SHA3-384 hash: 0b73482da4e48a0c098172c2442c6bd297d27794ac31d3ffd3a1e69276a1d1c3dc6a42f28b02d392fb596a8f9796c771
SHA1 hash: 84a46946b43b72495ee92255b77f4a9eb16d121f
MD5 hash: 4efe5bfd4b2d1d6a8a67c776754715c0
humanhash: fish-robin-lima-football
File name:requst for quotation.rar
Download: download sample
Signature MassLogger
File size:750'844 bytes
First seen:2020-10-15 17:25:24 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:2TxPmJ6eubzVfsfMQO72xfGRRVmzastnJmMxHyp/5uZa3xlQge2ArDVWQo1BswKw:2lleubpsfLZ9+stnJbg/oZa3zHqkQofd
TLSH 7AF433EE70A08A1C69C8D5B6C7E5E5F99A37963C30785A5CEBA0DD0700207D9FB325D8
Reporter abuse_ch
Tags:MassLogger rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: s111-ir-cpanel-trade.maindns.net
Sending IP: 185.165.116.18
From: ADEM ÇAĞATAY <info@dortem.com>
Reply-To: purchase@dortem.com
Subject: REQUEST FOR QUOTATION 6674 -29.10.20
Attachment: requst for quotation.rar (contains "GIf938_NEWPO939.exe")

MassLogger SMTP exfil server:
smtp.gmail.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-10-15 16:54:38 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar ee89c86eed2f5114c759a47aa7f49a32af7c2eacf3299c6e2b1b08f54cdb8d9c

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments