MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 663fcd5d44ca098fdb0cb35c7fdca638d01baefb3872d31025951ce7b2da1364. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 663fcd5d44ca098fdb0cb35c7fdca638d01baefb3872d31025951ce7b2da1364
SHA3-384 hash: 0569695dab9e28122b40c3eb2594b07926ac13a69b9fc80a26ca78be1571fd55874a244aa6f6246e51fe164c4dc7ea0f
SHA1 hash: af4a2f201027a480da11f2935474f9f176394781
MD5 hash: 0c2946288c12611c6b59dd4fe13f4181
humanhash: september-angel-blossom-glucose
File name:PDF___________________________________________________________________________________
Download: download sample
Signature Loki
File size:260'772 bytes
First seen:2020-06-03 11:22:34 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:c5z72IVepryDRGrQyO6d2DmOvO5k6GcyrAyQHSrhalvcLO/:cFi6epgR2daY5k6GnvvreT
TLSH 4944232CD374C90080D87EFD922F8A3D3F44A83FD6476A73EB36606A5EB524595D089E
Reporter abuse_ch
Tags:geo GRC Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: e351425.name-servers.gr
Sending IP: 195.201.38.252
From: papapostoli_anna@scitec.gr
Subject: ΤΙΜΟΛΟΓΙΟ ΦΠΑ
Attachment: PDF___________________________________________________________________________________ (contains "PDF_______________________________________________________________________________________________________6584746474.exe")

Loki C2:
http://mecharnise.ir/da15/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-03 11:37:40 UTC
File Type:
Binary (Archive)
Extracted files:
14
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 663fcd5d44ca098fdb0cb35c7fdca638d01baefb3872d31025951ce7b2da1364

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments