MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 977d67c533ee62147f1c941b680a11e900ed83574bf3e2c3a29e842f25c4779d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 977d67c533ee62147f1c941b680a11e900ed83574bf3e2c3a29e842f25c4779d
SHA3-384 hash: ba6de44fe7b6440d15332f8fe85a7cc0a0953b506a95b79aea3b4bf5f97550b2aac467d6da0658af42902dec8e09f3cb
SHA1 hash: 5e819932f512fd0c1fa60f2e0ae617ecbc370394
MD5 hash: 664485aa4a48dd73f5e9cc4044baaaa2
humanhash: twenty-lamp-nuts-nineteen
File name:scan_004768.pdf.zip
Download: download sample
Signature Loki
File size:25'070 bytes
First seen:2020-05-14 05:59:29 UTC
Last seen:2020-05-14 09:34:11 UTC
File type: zip
MIME type:application/zip
ssdeep 768:bmsCt+WmWIFN5766RCIeCaqb/gaX1qol3oUHHhV31+1:bmtYb75cqjnXQK1HhVy
TLSH CBB2E17E758F568BF870287EBAA99147C634C9D0D7C4AB84F6761734322B0532A8C2D6
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: gmail.com
Sending IP: 156.96.62.53
From: (Ms) Franziska Glas <info@honoraudit.com>
Reply-To: (Ms) Franziska Glas <irifo@honoraudit.com>
Subject: revised product enquiry
Attachment: scan_004768.pdf.zip (contains "scan_004768.pdf.exe")

Loki C2:
http://javadijudo.com/main/wp-includes/c/fre.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Grp
Status:
Malicious
First seen:
2020-05-14 02:19:14 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 977d67c533ee62147f1c941b680a11e900ed83574bf3e2c3a29e842f25c4779d

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments