MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdd96aba675606113ee424eb6c31f8dc47d9afbb0e83e8bebcb6299f2fa35cce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



MassLogger


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: fdd96aba675606113ee424eb6c31f8dc47d9afbb0e83e8bebcb6299f2fa35cce
SHA3-384 hash: 08207b9a13cc7d3e1844680f4104e16ce61b203f028c4db3bed035366e59878fba21ffc5ee0349699d21f7f642f57e93
SHA1 hash: 1d1a3ab4b6932d9f52f8f7e4566c183a1557a5b2
MD5 hash: 8ca4aece905648797ac6ee4758bcd75e
humanhash: spring-juliet-fruit-ohio
File name:BL2038784680.JS
Download: download sample
Signature MassLogger
File size:3'182'477 bytes
First seen:2026-07-23 12:32:45 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:t+3wgGKE7cFLz3Om3HCNENK0uUqS9OS21VQKONffzteJ72SYWOV+:0nGKE7cFHJKH8OSsaKOFfwJ6pV+
TLSH T160E5B310576460737365D36CD236AEB8C00E200736D9CB88305E9A64B51EE97A7FABF7
Magika javascript
Reporter James_inthe_box
Tags:exe js MassLogger

Intelligence


File Origin
# of uploads :
1
# of downloads :
178
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug downloader dropper evasive obfuscated packed repaired xloader
Verdict:
Malicious
File Type:
js
First seen:
2026-07-20T14:54:00Z UTC
Last seen:
2026-07-24T08:06:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.Ravartar
Status:
Malicious
First seen:
2026-07-21 02:44:49 UTC
File Type:
Text (JavaScript)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
masslogger
Score:
  10/10
Tags:
family:masslogger collection discovery execution spyware stealer
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: MassLogger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments