MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 62d95203521d0e0de13d4b70689b9ad5152eb31af21dcdc773a79be962664f5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 62d95203521d0e0de13d4b70689b9ad5152eb31af21dcdc773a79be962664f5a
SHA3-384 hash: 36885f7fd27b97b3bce8233bb5ce0b1a16d7e9089b6ea1bba38f5178f0889e0223e208bbf63cdeb4e31df34c78855d8f
SHA1 hash: e09796baeb1c164ed6b55f8c9872623e3467fcae
MD5 hash: 038ffea38159f39316e08761683fbf86
humanhash: oranges-hawaii-lemon-quiet
File name:Εντολή αγοράς 87985614 με ημερομηνία 06222020.gz
Download: download sample
Signature Loki
File size:238'708 bytes
First seen:2020-06-24 09:12:46 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:RwQ5AT/TIOv06YaMnh7x7DrSiPp4V+F1vlJzjimGN:RwQ5w0KqgSt1tJvimGN
TLSH 743413F094253D9866A3C4452C69E5CFE50A7A73DA2C1FAA55BC2C399AF0131CC7FE12
Reporter abuse_ch
Tags:geo GRC gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: weddingingreece.net
Sending IP: 95.211.208.25
From: Katerina Tambaki<info@weddingingreece.net>
Subject: Εντολή αγοράς 87985614 με ημερομηνία 06/22/2020
Attachment: Εντολή αγοράς 87985614 με ημερομηνία 06222020.gz (contains "Εντολή αγοράς 87985614 με ημερομηνία 06222020.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-24 09:14:06 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 62d95203521d0e0de13d4b70689b9ad5152eb31af21dcdc773a79be962664f5a

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments