s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1 high

📛 Threat Title

MassLogger: specification.exe

Category: MassLogger Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2903040 bytes. Tags: exe, MassLogger. Reporter: lowmal3. First seen: 2026-09-24 07:48:05.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1

IOC database

Type
hash_sha256
Value
eb278f0b405f0177a6e6043b26d77f7542a0628a84672e8dc38fe235abf30df1
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
MassLogger

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 ad673ba9a9e59211fea6d19cdb384db1f798508e

IOC database

Type
hash_sha1
Value
ad673ba9a9e59211fea6d19cdb384db1f798508e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 0d329a87c588fc8b681bbd3c4c4f6959

IOC database

Type
hash_md5
Value
0d329a87c588fc8b681bbd3c4c4f6959
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2903040 bytes. Tags: exe, MassLogger. Reporter: lowmal3. First seen: 2026-09-24 07:48:05.

Remediations (10)

  • web:any.run

    MassLogger is a stealer of credentials and sensitive data delivered by phishing emails and acting evasively in the system.

  • web:blog.netmanageit.com

    A sophisticated variant of the Masslogger credential stealer malware has been identified spreading through .VBE files. This multi-stage fileless malware heavily relies on Windows Registry to store and execute its malicious payload.

  • web:cloud.google.com

    This first stage loader eventually XOR-decrypts the second stage assembly which then decrypts, loads and executes the final MassLogger payload (bc07c3090befb5e94624ca4a49ee88b3265a3d1d288f79588be7bb356a0f9fae) named Bin-123.exe. The final payload can be easily extracted and executed independently.

  • web:imtr.net

    Analysis Summary # Tool/Technique: Masslogger Fileless Variant ## Overview This document summarizes findings related to a fileless variant of the Masslogger malware, which propagates using Visual Basic Script (VBS) files (`.VBE`) and utilizes the Windows Registry for persistence and operation, avoiding traditional file drops.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Block known vulnerable app versions as a mitigation step in Microsoft Defender Vulnerability Management. Learn about prerequisites, block and warn actions, and how file indicators prevent execution while remediation is in progress.

  • web:malware.news

    The Masslogger fileless variant shows the evolving trend of info-stealing malware. Delivered via a .VBE script, it abuses Windows Registry to store actual executable payload and loads that payload directly in memory without touching the disk.

  • web:undercodenews.com

    The Masslogger campaign exemplifies the ongoing evolution of malware tactics—from disk-based infections to fileless, in-memory threats. By embedding its payloads into Windows Registry and avoiding disk writes, the malware sidesteps traditional antivirus tools, which are typically designed to monitor file activity.

  • web:www.pcrisk.com

    MassLogger (also known as Mass Logger) is a malicious program classified as a keylogger and 'stealer malware'. The primary purpose of MassLogger is data extraction (i.e., it steals information). The data targeted by this malware depends on the cyber criminals using it.

  • web:www.seqrite.com

    Deep dive into Masslogger's fileless tactics: spreading via .VBE and storing its malicious payload entirely in the Windows Registry. Understand its multi-stage attack and methods for stealing passwords and private info.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.