MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49c5ffabc91df9d8955a65e220b7393a38f39bba5f7197e875763480d6be4bb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 49c5ffabc91df9d8955a65e220b7393a38f39bba5f7197e875763480d6be4bb3
SHA3-384 hash: 3f80ba5bbd2b3b5b0225ae2ec87faa4348511f0c221d6d84d7a4eb64710c06c2ff02e1bcb1152c84f8effe6424396e5c
SHA1 hash: 7b19ea4bcab11b5811447ceb539c2f6914849006
MD5 hash: 7e34a34a1e948de814145be40b409c8f
humanhash: crazy-tennis-robin-coffee
File name:slip_00927 MAY.rar
Download: download sample
Signature Loki
File size:300'379 bytes
First seen:2020-05-11 14:44:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:XXYMeEIJT0g3lDRGRxe3qX3YHxfuNqRglc1jF3JkKlYWHlGkA:nxeEIJv31kRiDxfuNqScFZSKlLlO
TLSH DD5423BE43231F48338A72D4BB23FDEC13005E57458CA68565D5AAF2DE1B45099E3DB8
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: sadana.dua.rumahweb.com
Sending IP: 103.253.212.215
From: Personalia <recruitment@antam.id>
Subject: PaySlipEmail M1
Attachment: slip_00927 MAY.rar (contains "slip_00927 MAY.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-12 04:26:41 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 49c5ffabc91df9d8955a65e220b7393a38f39bba5f7197e875763480d6be4bb3

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments