MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
MassLogger
Vendor detections: 15
| SHA256 hash: | f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c |
|---|---|
| SHA3-384 hash: | 36bfabb562f4c80aaa6f85d180fd6a63b70c5f87957d89ef2f28febf0fb59ba6d25cb521a0395aeb6e819156c8619459 |
| SHA1 hash: | 59a2fc28410396375be78b0b6d31e8fb927ad01f |
| MD5 hash: | cfdbb198c74582042303667d422f1b1f |
| humanhash: | sixteen-table-minnesota-nevada |
| File name: | SIP_20252701.bat |
| Download: | download sample |
| Signature | MassLogger |
| File size: | 1'533'448 bytes |
| First seen: | 2025-01-29 13:57:32 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'461 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 24576:izITePvRisyUgObx1edaWNQ6DMKFTGavfetqAYbUWU5gf57F8QlaAm:FePvREOVQdNNDMWTGan+YbUtgfNtTm |
| TLSH | T1E465E0C13FA4A708CD3E7630A595CC7163B12629B461F7E6A6DCB797368C3118E19F0A |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10522/11/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe MassLogger |
Intelligence
File Origin
CHVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
f0e65a838c01e4741493c605aab2232854d22a14d913374a2c61f083b35d7aa7
98a11f5e0943f5a8e0475b4c7d87b5f67a1d39f7c44e564d86df4ebd687686f8
a7a1f53264ca6adf45c493ccf8db7da322b51c094a305ffff264db5df146edcd
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
496183edd167fc6543a66bfc47c6a486eacf7fcafa9149d6d78c590e6d6b3be2
cff8bf19e834f403b7914c1fae20c0089b2a75a29a769c1e46aa3bb234171d1b
19ccabe99d3c6dd06c2c9f3659a7f196afcdaf84af869e573cf3545df80b997c
84c1d9c18d8e90a6e7531688800c148405426d2dba70e7218c9ee34fcf076e9a
06d1d5e5a8e641a62df3b3282dc437d24d48a31cc60f691c760023429788ec6c
0ecddd957a515d3d3ddc583b3f451d56f56273cfc844c13a8cb0b78d10b3c52b
6601f8f872a1514a98b8166c3ba55d63db44d5e9310d00f91ccf770e24742feb
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
5dbde839c07b34a42667935da05d18dbf85e630126ee3c649383a44aaa9b6602
3b1b0c6e463108f7a2f9d683fd69ebb175b10e5662b27cc7e8511fca4157f407
eeaf38c14ff27a1c50d173c3ce5c5803517d8015cf1e6d777c0eaad1eead4af1
6208e1d4a0b694b7d2a70d312f8472b2c2acd0edacbd5a2344199672d7dd84af
c53b13442d16e522db35af6431d5a3d9599206db9975245b9ca90c43d4c4645b
f42de693aaae005ec4dcf3514621f8573b422f3a3ad1bb1af370acc7c5cba233
28a65019d2736dd82fdb229c9e6f5ff053c25e095d118ae03359238f44ba22d7
fcbbc6c9a426352d6a329d9a0a055cee18d66ee62835e3d00499e4ca52761c1c
7c3a286e6c2a9e2b50a81e67dd03ba27e6dc6fa7bc87f45d0e51056252823cc1
8ed16a383adea236fea0ef757127aa5449e223ef29617e0b584286183143234c
4e591799b96dc33af9dba4b19fcb173c9c79da52b645ef063e0f6734b999a91e
d80246672d337713cd5dbae257d6cd81acdbb3b4328141a1bec0a735b9618d71
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
4ef83ac7a3bdee1a742de8de749c5afa4747acc20f8937301dcba291d1ef83d7
2f71acafcf825697cf29e5f93681f9c7128d49fee3e04a20dd506042102734a4
13fd36bd0ad2ef303ded0dac6b7cd6d4326ffebb08ff914eb44a6e75c52e8289
282a05d5e79cd8a8fecb470cdde28f483cc6fa7d70785f6e6e5e3de3dc39a979
89260b07ae5d0858db8a14a8b7cd9e2c1bcd064f5596e7e0cea1665c7f0c496b
a1333650518e3e435421e28233c84f8a5a1ca03607c5289a01da3f86e4046565
771077ce6d2c6eab4908e19af87680fba3491ce6aa9cf976d82afae3a7cdfa10
17c4031831d4166a50a72b65ebdb2a4825645a3314ba5907f46329b9da9b2a06
55864751fb6be8d2789f4e3789bd2794a9e7cbcf39d472f6a4da1d4ca2f50758
12bd2e88e60fb4e93881164b51c270121034f7ed01bef4ae0741abd8e532d77c
1efe29ca00c9e7c69c46dc8139204716a36b6074647f3ec4fb06e2ac6576d496
4fa5ea6373a2464ae2a7f499d1e19cd27f6506df81bcbde80567b79d7e211520
dcb2bc8fe4ca10f50062e50786e71539aa41240448d652876c96ce970be79162
001abbf49585db1553929901f5cfc1465e504fea17f6ffe78a344892aece146c
0873358f1252f19f17bf03e959386d2c39ceb8b90b7a73d0de11456082c2730e
0c2b52146f60798b2d069e7c660be0a95a9d7a970d75ac489a1dea7e97e441d2
f8259be27bc5c5ab89b1f8101535489f28799ae8c1251fb00aa9ec1d6389343a
e48808b99478ddce1a031afa8094dfc6d4d5002bd012e278e741b5b59794044e
976d5e9ce2356934688e015c90497c08d5334715c5d2235d5d13af314565d3d0
8f41896e69d1f83408cf68e4d6fc56849a6ee6b86145e7cc68d6caed660ac582
a14ecc9756de5e5e89e2f12839750c554f9d6b2e45773475d096d6db1fd92c04
061bc2648b58846a4dc7cc468cbf1b4bcd2be744502ea0775b705b04ef536dfe
60ebf1dc0d303257b79432e0713134f71fc044aa38f2dc85e55d20442c01add3
ee55e7f496b05d9bf98cc381e621483f549f9452d94d6ce32d4f3b59c67bec57
609bc44c18519741abb62259b700403e05cc0fd57b972ef68ca6ae8194d27f2a
4bd0336e60490dc8ede45e9ac7aeacad032fb72e1c4401552a9d4d7d52c09054
34444d4292fb1f61fad6019625d22b9b88868e8af67aa0a84f1319ce8d571f01
a9173bd9c5fcd609d03021f9e23634542691b79a791c4855fbfa248a940eda14
ca4c4cc60005ca88e582734f5f0232099184cbce1effc270fa761367b9029bd0
45aa9c752530b71775bbc59a49604fe2f8f10a3c98be4e3d789d307eebf69b9a
447174dadd9697274ba6e102647bc6847d816b63d91bd0f35d29c5c3a3401ef8
dbf83094e42dc231fe1a1b00f3fe1e4cbfaed8757afdb3d5a166e91d3b3733ea
b3d2c06489759b1433bcf9aa38c9ba9dfb400bbc4ff1deedd960f3c3dd606518
b7ffe514c90485438c522430e88937fa81bc965e74161025eb18f8c1a85275d3
490c785be9863eb038433c2a125ec62809a8bbb25f4ddba21f72772e034f577f
6c2cf6bf017b8e9c8731b0b0bc1ddfd20c14e381d5282832d5646ac29158cf73
c2aa6c735713c7b8141a6f98467fd4a41e72c536dc2d92c591e47b06ba2666b3
079e89bd883be60d3ff2dd26ecf457b181003d8317366f87995663dec23c7252
56a1a9b139520b6c51ac67413d6bd6db87771d1af9d6994290815ad99dd89102
c38b465d0723cfba8e741705451d5b4917f09640664adf5bda6c0e48026c6b3f
467d77d35a6fc815ecbd60b0b320d7ca06e0f8a340c2c3285de4c0430517f8e7
4336ddb80f3875340305306f98bd57efcb38a2182153d71308957167a295c070
d0d2ac5af6ecfdf27de6c45ab86d521294350c5a64942cd15bb5d9a1ae23b0f1
b30e339a7ecbbf9ea338c915cf1e3f8e6b6740b314ef1d08e38b1694e3446163
737981c73007c1fd4dc3cf2d9a5c79cb004fe48bdf3cba06b4ead50b3a57af13
389d68ade0d98fb86548dc560ee291397729e0474a0fcfd3299c9d534e6f1234
205e98d299b32e102e3d6fadb9659f713601f8f713be02cec1ec0f437d3be075
b8a1cbfde7cd26809f6a8a90d88d09c0558fb2417dca15d7edd5e3eac3e07073
6cdcf78d540c146fb0319b5539d1bf930c2e59c42ea8953066c648a0b65ae460
a91cf2a4699e93a3101762f542bf47b51d8ac09f8e78eaa2222c36807e0c0e72
565dd0687c5447e3714250520bc29577e6516b8bc597067ca0dff05274896b4e
b35f831b82f4648f91b37d8b8799cb26d30b069a52cf12e14ba9b4c06e8fb571
9a71da6c174ed01e2bb5fddd7bc7d2ff7e6a988b8deecd05c6935373192573ab
8b25b0ed0e18bb24684d10bb3afccf6e6290c95e89a79733914117e2c7b46b09
6a19ede919d3ef32c74ddbcefb4bfd3ef61ba2a86739978ed337639193678edb
0cac75f1f61f9fcca09695de695e469d62f7e73147ba678f7d6dcb4eea80389c
75db64719f3225f1e42a86bb7cca56871f757076f81c42802e22a83629ac4fbb
a50041a2a0cccb573e80cb188f35785613ac38230cd4d0031f738855446cabbc
c2d06459896ee441feef919813800bc4f9c382ac08e28103bea73b675e556ab3
27e9c5e774bf0946e99a7f34d14ded33ca1c236765fbcfda83e234d70d15c652
5b2a4d07425414d3e00bfe400df7cf20526f32e9b29f4b7eefb07ddc38720a15
a883ec7d3df1913ccd847c0ab5d521170adb967cb09cd5b3845e04b50aa4240c
b8dbf3db5d56d847b13c3e517dd9e9e396038948ea1189e7f57c419f493c368c
36c3f143edb273d0d6cd6738e0357ddc19b86857de46871ba96bcb1a8256b1ac
35bba0cdd40a31e401d3e668676f3e6b5c51ea9bd4850e46a6fb0b391862838a
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
774b328fd5904bd0a7d3954bf9321948b43dcc3091db995c27fe47e360d2b7aa
16a43aa836bfc334a9c67a4a6cbd25aa461b9332b7dbc5271afd75119c2a3521
42a78ab84a5fc43e1b379a2968a32f272492c860f0602649d25374d521b4b83c
a689d2c7fa2cc3712ff115a0dce0cd90c5d55c92bc87e7f24dcd05ad4a38db63
6f706398207b1fd3a00de5f859dc840cf8e100175fdabe260ebb96db5980f03c
10a5c29d6a44de5b996598f71820bff8c29cc6b5229d2c7ec0664b601d81068d
640cd2bb3f4726760684d6e3a5e56e28e37860c7d377fd18e1f428d31b47a468
4c9850cad6a1efce3f23362ff3f68fe5fee556e3e344e867f16ac821701e90ad
629e839dca37071336e2ffd8bd9250443eea5a18cc317a0edc85a3d4aa59cba9
6c8c1ce5b36a379f6fd545629aa03270575b179e4194c31f6db163bf06de6cc6
000131c03f015a78307daa5d0d21c2fc6b286f54a51b5ad14b237433e77b3ea6
ef9f3bb8a6695a4ac654b7218954695432faf87784d5c78f8d237a4532a466cb
fa3e852fa9dde2dde0c1e2254f81059f8c2f1088596e0fb9aa2e37583c26ead5
42bf798312044d50fdcd35dca04eaa7bf628fd71e876fa6fa33b95e593d7526a
94fbf90615b1baf84da26854c9c7b72115eaa12eb8392d898c7689f433980120
8b0f47fb5a7f509e14dcbc3eb94ed4d09602236123147012ef174701470ccdd3
10b78bea9f7acc71be5868fb39e4941c06ec08c4b0ea25b0957ec6b63fe37e20
1e1cda620f33f8a4e039351b55ea841fb09e0212ca2dd44cbbcd52fc88ef8f61
a8c8535f49c3869518e9d62f95086e5ac36526ea61d4203aa8d2077d33ae9faa
31c25e01cbaaeadccfa1321680bbfd51c17b876859be87fff22b2db8ee1e117c
e2fed3e4dc387c2c5ed61ad006a9c346eca49f388636d31e48e19e81469d365b
6dab8b138cc6efc4956d434d6992307f17faadc887bb3829e950daf8bfd5f46d
14ce31b551f4f39bca04ece6143ac80a3943a957d9a6056c88b6857daf60b784
683e3979cc09db086095cbe840901b82951df941ed461f89a67b98bd0ffe5ff9
342a6c5178eacedd99cd66da3bd81e767d0aa311441ad2089b087def3f5cb088
36b2c227683d3aea101fb59edb33edb1ba28ec0753a32a5ce42b1959d6716965
88b2b7e8b37a44b6b3ed65362a01936ff5500ae073ccde2c6a5c51b0afc05d94
3600d33c7e14a371b391e1e949a16454a26014007dca981bdcd177dbd234f797
1e90ed469f2242b4882864a20ab1357789b1851f14074cc97a263ddae613a53d
b58a7d4bb391ebe2243a86ea92641445e98a4da3e51abf3d2c905fb8ac0dd9dd
19c81289b55d23365b8c4f7c6f951063b3aa05c10a4d8025dedd0893903fcb59
c95f3abb8db4e2a88ca3d533b42608b4d466d70e1e92fab9d234e6afb6ffe011
7fc8b3746ac1a4ce5a1b211f56034656c4017aef413aee72b0884ad5f0a94054
676528e924dfe6e5e119f33ac5e7e8ee5661f871759e4b32ac27b0a1d243e329
60bfb47f60c7f0a6aa8185734c85849995f497117e38ba2c2e9fdeb1330b0cf1
12cb84b318ee85c5d7b4ec15d5f6fb2c26a43f93c68e98c6f40c2e2b17bcdf65
5dc75fc4ff5d018e6f56ed3f2676781e2ae1a341a878ee5ef36513376b75a310
0d6a9673eb3db83be393b8e85fceb372b5fbad79ce1c56bd92ea4b6b3166f657
cf8609a0bf3ca9ed3e5e39abab534229213e4df0316cd0478032cf59e0f2f3dd
0531f60ef00a3998d4932da7000a10630fae4b355cb81db091008f3899e039a8
0b9d81ffc7bd0ddeed01b5a0adc279cd4a79003ce9253fc7e096fcdc63ec371c
004de56c87ec09f1022747d6713c26328397dec1a683f76aa178a48da776c82c
543a5190118c546db54b03846c3927a4cefc69809b5854fdd0fecf1763dfed2f
ee6be21c96c562717375ac6d428d00777826ddd74a59b8a1559eb353950f5d93
5c7dfeaaab049b0c4a2b6fe06c7d6d8d54202ab9b5ba637b73faa01bccb5debc
0f5ddd1e5c66b90c7a37c276228ef498be1297d5cf3823afd72b0ad08b08987a
e0f397c466a112a3c04c99cdd5a1fbacd2131a90d520d5245f5d0a2336e53233
8032eec5f8978a6eb901f96583472cc3bef407b41a3357ec253b8204305b69b2
b9581e9af28f052e463acd6117271db974830bba5a7ba5825068596947e872bd
0fdc25f5430a61cd969c0bcb2e5ed6965d4eb4dc73374649eeaf5a6b77498d6d
b4be7f2484d838df9503c7864f809acbaead8a110cf42a4e6481a01b5f4f9485
3bbeda749854caa304bb1e8b968971a7e84359f98105c9ef80d18033adcc2f09
ad2f3629f617763f45abc1be39c4a28f581ca8d0efb97e3bde2ad33106714c85
0004912ccca96809295d0383d2febcd100a386ed262d9912f1a02e886ae460c0
195ee9a9f96abb146c2c217c659c7cd66093d607b9a64a1ffe976a32eee81b2c
4e007a23a0658f7417c1767bf2f2a0a3722853216e9a00489f79d57b555acc9e
f68c0c40aa651d080967ea4ea3c389fc1e3dbafcd097ac10f01374d0f6ae52d3
862a367b1e130dc47d08a2d4ce26bec8d85196f00c1a3f6c0df4fc5f099139cd
29ce0132efcb5e1aad146065672d83b6b4ced076f1c91a851c8b34a30e7e08eb
45def37a33ac8c66332d64929636aa908916c5a4c4b17ff5724de5564d066105
593995d24730f261cde9c772b7fddbbc57b02d36418905ba7a95b78609d4a258
8835d6d5566c121cb4fd76ef710de856b803636037b510524d3de684071cd1ad
9155862979f292ea527e4107a7143bd9b54c66511a1aa1b04a06f924a4ed901d
be9412060a9d41f496e907a637096255fa848a8ecb4bb4b35043f2e71ca871f6
8de72052a7f6f26cdf6b3a1850902acdd6856fe29b94871fd9eb3fceca479fa6
66c79ac72ae7d06167cff941e73c5f3ba525606316b3f9bfbdac8db3031136fd
5f97099c9597917ad3091e70910dc93ded0181185c1878fa4dfffaf540b46e4b
ccfaea5dfcfb212dff4902b0392b7b793bec6f56c5d7162fca472ed00995d381
c5f3533849c988dc9812857c7a8e6359d82cf650955eec6d14661426e62bbde1
fc555917ce12a41761d6e21ef399d5be7dce2da3d15a05b2ce3fff10abcd77f9
80b3c8d9dcccf09f2cd697875d417ecfd90dc7ce3132ef10bc5d6f48510d19da
185a716f245f4951e997e91ca747ec2f52acf4fb0adf594bccd9c8acbfacf677
b996d0418d6d8ac7d8f9ce4d09d0eb1f0fd1b30d733499742a41a9c6930521b4
e5406c9136408ddbe90ec00c45b1291e3e847826ce1be6c39b77327d135e57c2
8ef455d1383249717a5d6215a98c176da08d5cf9f2d70f6d3ea24368b36b00c5
038849db19818c7136fe0a551b3f1b9ab11d51390ab2f4197f9f7c5ff16f6a8f
987d80fbc03ed5f7612a742982367ae5f354237968d23b2fe1cbe9440946497d
115ecc94cd420b4f77a75eaf0597c9b37be273f5827bf96d8336c4a5827307c9
8d553fa3b10c79bce846dc321c6ff9613813119ea8216a9c8667b60decf467a2
f40bb32fef35a7b1b5cee5efffca77d13827a7703f7ecc846e9edd9bb648541f
01e631c29a801330b7eb8f5904e171a8d47b044754153792955a459c25db112b
f00dc5ff445b6f7e880b09c5d74c2d2125832d736c3df1d3a069f3f81bf8873c
9851d62bf33dbe25f0502a068bde8acabdb58fe5230a31ac0942efe685f1f54b
2f712c6b725905241f86c0a76963dc5053e59d0dbd1b0396dc2e88c3d94f54ff
1ec8e13c55c7d0114d1877cdce2e18be355218edce5ae2403ff928305799885b
5d19080b4f02064df1e03553721cb9269413ef21e5bee832d9dd5688f01db5e6
8de4312c046f3b3586dbf7a813d5678c2ad5dd319d476f4d64b403dc0d45f714
1e12346e4000bfaebac977089464afeb82b3729a90bb6ffd66dde49b2da297e2
8b903abd92011f515abe01bde91dbf27d2f8037e7712be038bf7bdad420b5e6e
ef522b08a1410eef91c4e03d3241eb012720d8e16ca363dd93a48c2b5c92df1f
f99d68393189fed84f6b667127e531a5f9efc410598335eb06a6b973462237e5
a5c29abda5dbd2006117b82fdadbb70f42354298b49019b73c36e31e8c6bdedb
7f4009e7a332b49ab49007e5cf74a87a6a7bf5a115a0acb621ff8657908ea2b3
81772deba6bfc78c34c1f83ecf47c84337e0b7592f96c6548b3e865a0a424eb3
0f0797053ff7a7b8e0bc5e75a5cd8e2eb91739101486374e4209c29a92fc2d66
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables signed with stolen, revoked or invalid certificates |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
| Rule name: | Sus_Obf_Enc_Spoof_Hide_PE |
|---|---|
| Author: | XiAnzheng |
| Description: | Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP) |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.