MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79904a1f0449aa2b4755d08925084e4847894cf6d8d82bab8b2ce98de012dea9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 79904a1f0449aa2b4755d08925084e4847894cf6d8d82bab8b2ce98de012dea9
SHA3-384 hash: 6ac018ffb0ab0bbed06e5721b4e651b98c244d381eb50f88e5f03ec1743d4a6bb44b64b4df34064de8cf1f03fe5cf9dc
SHA1 hash: ce5368b75995eaad5eb373347689ad1908cc4ff0
MD5 hash: 250a6c2f9223a2bb11327688a01cd32d
humanhash: kentucky-hydrogen-white-fish
File name:payment against your INVOICE..cab
Download: download sample
Signature Loki
File size:184'765 bytes
First seen:2020-05-14 08:15:17 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 3072:7nmt0A4dwBde+0307yrd4Z4MhHrheNB4CSrMmNzM+Wg0cw8I9CDiIvTRZ74LgVoo:2vwt54yKkSrMB+WbGiI7mvo
TLSH 02041249EC9341B2852FA19563B78AB6B9723C3E5F30CDBE1D61EE169538035264DC33
Reporter abuse_ch
Tags:cab Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: rawji.com
Sending IP: 185.222.58.142
From: Jessica Hu. <info@rawji.com>
Subject: remitted payment against your INVOICE
Attachment: payment against your INVOICE..cab (contains "payment against your INVOICE.exe")

Loki C2:
http://scarfponcho.com/windows/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-14 08:36:14 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

cab 79904a1f0449aa2b4755d08925084e4847894cf6d8d82bab8b2ce98de012dea9

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments