MB-eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1
high
📛 Threat Title
MassLogger: specification.exe
Description
File type: exe. Size: 2903040 bytes. Tags: exe, MassLogger. Reporter: lowmal3. First seen: 2026-09-24 07:48:05.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1
IOC database
- Type
- hash_sha256
- Value
eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- MassLogger
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
ad673ba9a9e59211fea6d19cdb384db1f798508e
IOC database
- Type
- hash_sha1
- Value
ad673ba9a9e59211fea6d19cdb384db1f798508e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
0d329a87c588fc8b681bbd3c4c4f6959
IOC database
- Type
- hash_md5
- Value
0d329a87c588fc8b681bbd3c4c4f6959- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2903040 bytes. Tags: exe, MassLogger. Reporter: lowmal3. First seen: 2026-09-24 07:48:05.
Remediations (10)
-
web:any.run
MassLogger is a stealer of credentials and sensitive data delivered by phishing emails and acting evasively in the system.
-
web:blog.netmanageit.com
A sophisticated variant of the Masslogger credential stealer malware has been identified spreading through .VBE files. This multi-stage fileless malware heavily relies on Windows Registry to store and execute its malicious payload.
-
web:cloud.google.com
This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload (bc07c3090befb5e94624ca4a49ee88b3265a3d1d288f79588be7bb356a0f9fae) named Bin-123.exe. The final payload can be easily extracted and executed independently.
-
web:imtr.net
Analysis Summary # Tool/Technique: Masslogger Fileless Variant ## Overview This document summarizes findings related to a fileless variant of the Masslogger malware, which propagates using Visual Basic Script (VBS) files (`.VBE`) and utilizes the Windows Registry for persistence and operation, avoiding traditional file drops.
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:learn.microsoft.com
Block known vulnerable app versions as a mitigation step in Microsoft Defender Vulnerability Management. Learn about prerequisites, block and warn actions, and how file indicators prevent execution while remediation is in progress.
-
web:malware.news
The Masslogger fileless variant shows the evolving trend of info-stealing malware. Delivered via a .VBE script, it abuses Windows Registry to store actual executable payload and loads that payload directly in memory without touching the disk.
-
web:undercodenews.com
The Masslogger campaign exemplifies the ongoing evolution of malware tactics—from disk-based infections to fileless, in-memory threats. By embedding its payloads into Windows Registry and avoiding disk writes, the malware sidesteps traditional antivirus tools, which are typically designed to monitor file activity.
-
web:www.pcrisk.com
MassLogger (also known as Mass Logger) is a malicious program classified as a keylogger and 'stealer malware'. The primary purpose of MassLogger is data extraction (i.e., it steals information). The data targeted by this malware depends on the cyber criminals using it.
-
web:www.seqrite.com
Deep dive into Masslogger's fileless tactics: spreading via .VBE and storing its malicious payload entirely in the Windows Registry. Understand its multi-stage attack and methods for stealing passwords and private info.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.