MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4e09e6e80223c9ca05931df6f0306bea4fc1b52ef54cd7341d122c8a8388f0af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4e09e6e80223c9ca05931df6f0306bea4fc1b52ef54cd7341d122c8a8388f0af
SHA3-384 hash: b145b8a68764f9688401fe907078bc0347262195056a39840dee1a2b6ce2a4a83881948691b228cfed5dc2d6b61f9e07
SHA1 hash: 94009c062e132f5391275cdd99b8f0859099d4d4
MD5 hash: ab8d6f4c54bfb4d9cb16777744c55338
humanhash: johnny-eighteen-freddie-yellow
File name:DOC8364726092_701.rar
Download: download sample
Signature Loki
File size:246'488 bytes
First seen:2020-08-06 06:46:54 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:AWpvGmFk2pw6X1PJTjX6VtkoH/+U01t4HZdynvN+t5DLpcp:nvG8p5lxqVWk+F45pt5DLyp
TLSH 3D3423A3816C132678C1525FEC13D685EF162A7A8125B377263CA6ED473E22C3AE35D1
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

From: "TOPWORLD GLOBAL LOGISTIC (SHANGHAI) CO., LTD" <lind@topworldlogistics.com>
Reply-To: lind@topworld-logistics.com
Subject: REMINDER - RFQ ENQ 30/7/2020
Attachment: DOC8364726092_701.rar (contains "DOC8364726092_701.exe")

Loki C2:
http://kibossuqar.com/kaka/kaka4/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Negasteal
Status:
Malicious
First seen:
2020-08-06 04:12:27 UTC
AV detection:
23 of 47 (48.94%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 4e09e6e80223c9ca05931df6f0306bea4fc1b52ef54cd7341d122c8a8388f0af

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments