MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f00e34e631934e78af79d4a5c4d8b448aa47b4de040299a5a4aa4606ba7c6a20. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f00e34e631934e78af79d4a5c4d8b448aa47b4de040299a5a4aa4606ba7c6a20
SHA3-384 hash: 8cda421206f1ce5f5d5d0dd7a6748a3d92df1dc8e68789111889c64a2afd23fcce101873dffc07cae13c4b71cf0d93a4
SHA1 hash: 17bbe342747dfff1d5b10a8d686025578aaa2e08
MD5 hash: 60822559ec19e6b0893f2f7129e0a23a
humanhash: red-five-rugby-seven
File name:Inquriy Parts .rar
Download: download sample
Signature MassLogger
File size:911'626 bytes
First seen:2020-06-10 07:06:50 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:To9575Nid9seKY4/q9XGgZKaZbD7lmx5A+Zf1yG9+2AvpaiLpDzWU2Q5IykIp:Tw75EQF4XrDBeA+XyojA7liCKo
TLSH 291533170C050F39577D7644E9DECEE2329A3C64245A6D936234BEEB80390E3E799E6C
Reporter abuse_ch
Tags:MassLogger Outlook rar


Avatar
abuse_ch
Malspam distributing MassLogger:

HELO: APC01-SG2-obe.outbound.protection.outlook.com
Sending IP: 40.92.253.107
From: fanyeu@hotmail.com
Subject: RE: New Inquiry Parts
Attachment: Inquriy Parts .rar (contains "Inquriy Parts .exe")

MassLogger SMTP exfil server:
mail.blacklinepix.co.za:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-06-10 07:08:08 UTC
AV detection:
13 of 29 (44.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

MassLogger

rar f00e34e631934e78af79d4a5c4d8b448aa47b4de040299a5a4aa4606ba7c6a20

(this sample)

  
Dropping
MassLogger
  
Delivery method
Distributed via e-mail attachment

Comments