MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 08e040e259c70a4c661bee85d7f4f615e49127fb3e41756fa167e9924365018b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 08e040e259c70a4c661bee85d7f4f615e49127fb3e41756fa167e9924365018b
SHA3-384 hash: f438b1ef16720d434286fefa576e18d72ab430c36a4f00839cba029400ac859db6a57aa29a3b9b66a4afb3dd6645ff8c
SHA1 hash: 128c8ac69c54e62eab9343f6a991ec1e01b1999d
MD5 hash: c462faa9ff594a924ea0656c89dd8e5f
humanhash: montana-summer-social-bakerloo
File name:NEW SCAN DOC-0011591_pdf.gz
Download: download sample
Signature Loki
File size:344'260 bytes
First seen:2020-05-06 04:25:26 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:yXjcoq7EzXY9+t/fMTEAHtNEFPDqCy9/F30wmAiAgATkrRMycjbLtpaRdd3oRsLp:jmq6/UIq0F1y9FViAgATkrRMNLXE4RUv
TLSH A474230D885C4C6F9335A70B7A89D586A0DA73C878AE95FCACE8D565B93CCC3C4709E1
Reporter jarumlus
Tags:Loki Lokibot

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'429
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-06 02:45:31 UTC
File Type:
Binary (Archive)
Extracted files:
39
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 08e040e259c70a4c661bee85d7f4f615e49127fb3e41756fa167e9924365018b

(this sample)

  
Dropped by
Lokibot
  
Delivery method
Distributed via e-mail attachment

Comments