MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f617c592b6b7a2be78ba00a5e5502661574fa11ac2e6adc87d7a51b083e26b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7f617c592b6b7a2be78ba00a5e5502661574fa11ac2e6adc87d7a51b083e26b7
SHA3-384 hash: 4085cd3f566e94554dc6b260a8a9fef49aaee11a36d6339efbea824f82a463f38109379c26758b4372bc47bfe4d57243
SHA1 hash: 65dbab53144973a846be13803c002ed5657dfbf0
MD5 hash: ea1c9dd36c54efdc73c1f50600bfa978
humanhash: colorado-oven-sad-floor
File name:PO# VAV-OV-1907_pdf.gz
Download: download sample
Signature Loki
File size:383'304 bytes
First seen:2020-05-27 05:55:07 UTC
Last seen:2020-05-27 06:03:13 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:9QT9RAEldSJ95s0z9i4gZlP4Hs0H4TNp0VBQ4cJIjpn2PMnhX5qK1sqgsAjEoJdD:aTHrlAJ9Tpizx4HZY52EJIjp2PMhsnxV
TLSH 4884238F23690346CB036D2988B9D80BEDB340F212B7F59BBA02D3979774167DC5674A
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 02:45:34 UTC
File Type:
Binary (Archive)
Extracted files:
265
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 7f617c592b6b7a2be78ba00a5e5502661574fa11ac2e6adc87d7a51b083e26b7

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments