MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c11495253d796e7e61e629a0d72bf4d4c58076ace9dcca47cf36753af5f8f92c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 4 Yara Comments

SHA256 hash: c11495253d796e7e61e629a0d72bf4d4c58076ace9dcca47cf36753af5f8f92c
SHA3-384 hash: 7e06e2d764afa260332a87af4603250c1765bc4662d98de404107651d6fc2c05ab07f7bbf339a791a29253551eec6869
SHA1 hash: 550ee5d6491abfa3602590e42f3005bc8fedfe3e
MD5 hash: 92af8e4d1378f14250feebec8a916898
humanhash: delaware-spring-coffee-jupiter
File name:INV 3326GHF- from Outriger General Importers Korea for acknowledgment.zip
Download: download sample
Signature Loki
File size:349'642 bytes
First seen:2020-06-30 05:36:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:sg7UWWjQ5IkMzvC2U7XWA5kf/+M2oD514Xh7+zJ+4u9nW+bP6v+I:F005LM7W7XHsD2cud+zJ69nW+b8+I
TLSH C3742350232BD4738D36E76B760EC6DE7147CF4FA85123E14E662CA9A0D86B461B0F93
Reporter @abuse_ch
Tags:Loki zip


Twitter
@abuse_ch
Malspam distributing Loki:

HELO: gmail.com
Sending IP: 156.96.62.70
From: Sales Team <sales.outriger@gmail.com>
Subject: INV 3326GHF- from Outriger General Importers Korea for acknowledgment
Attachment: INV 3326GHF- from Outriger General Importers Korea for acknowledgment.zip (contains "INV 3326GHF- from Outriger General Importers Korea for acknowledgment.exe")

Loki C2:
http://coolgirlsnation.com/wp-includes/manba/fre.php

Intelligence


Mail intelligence
Trap location Impact
Global High
# of uploads 1
# of downloads 29
Origin country US US
ClamAV PUA.Win.Adware.Slugin-6803969-0
PUA.Win.Adware.Slugin-6840354-0
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/c11495253d796e7e61e629a0d72bf4d4c58076ace9dcca47cf36753af5f8f92c/
ReversingLabs :Status:Malicious
Threat name:Win32.Trojan.Injector
First seen:2020-06-30 05:38:05 UTC
AV detection:19 of 48 (39.58%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 33.85%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip c11495253d796e7e61e629a0d72bf4d4c58076ace9dcca47cf36753af5f8f92c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments