MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 acd438911825ebc76c2b42f3dac245381f1e91462f99d74cebf41a9c7ce4e9d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: acd438911825ebc76c2b42f3dac245381f1e91462f99d74cebf41a9c7ce4e9d7
SHA3-384 hash: 40cbf8790029d5c6329f14c6e13d257c29186f8c23ca0aaea2137c1e29941681b0394a368daa8715a224280358948cf4
SHA1 hash: f7edcd40dab4d216e9fd0b58ad3dab52f20308ae
MD5 hash: 90aaf0878e32ea619d6cbb6203b981c0
humanhash: saturn-moon-xray-enemy
File name:Shipping Details _PDF.rar
Download: download sample
Signature Loki
File size:185'560 bytes
First seen:2020-05-19 05:54:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:VO+7D3BMjT0f3cyMZWlw461vfUPlLf0Btd1VgYbdTR2nCoCvPazV3WA5s7lVxzBl:8+v3C/k3c3ZWlw461ENidUYbbWFCvXYq
TLSH 180412F5AE0BB1EB00623E19C44075AD99C6E4B6E6EC72C47EE1E07C18CD9906BD7361
Reporter abuse_ch
Tags:Loki rar TNT


Avatar
abuse_ch
Malspam distributing Loki:

HELO: WIN-CBCI69TU3G5.home
Sending IP: 185.71.219.69
From: TNT EXPRESS WORLDWIDE <service@tnt.com>
Subject: TNT Delivery Notification: Confirm Your Shipment
Attachment: Shipping Details _PDF.rar (contains "Shipping Details _PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Agensla
Status:
Malicious
First seen:
2020-05-19 12:37:45 UTC
File Type:
Binary (Archive)
Extracted files:
11
AV detection:
18 of 48 (37.50%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar acd438911825ebc76c2b42f3dac245381f1e91462f99d74cebf41a9c7ce4e9d7

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments