MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce73931f25595f2897c8b959fb1080cbb48a6a14f1e3d3a1aefd0266195f919f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ce73931f25595f2897c8b959fb1080cbb48a6a14f1e3d3a1aefd0266195f919f
SHA3-384 hash: e9689265874191d08d1013ff8cc617ea272cd0ddb0fb749d62e275fd7f9d2ea15b0d8c38013a20a4586338b46d21a60a
SHA1 hash: eda709943e7465ef1d0e3a22746b5f6b004f05cf
MD5 hash: 24cc96d3f164a897ba39769724733bb6
humanhash: edward-carbon-cardinal-magazine
File name:Requesting for air freight charges.zip
Download: download sample
Signature Loki
File size:176'394 bytes
First seen:2020-06-26 08:16:16 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:J8ROLw67TzBYdfwy19B7XJfdtvsd7XN1mzROxW4AEXlJb3er4TiY8ZH3ly02Ersi:JNw67TQfwy19BLpdWLN8uW4RJb34UiYm
TLSH F50412E0EEF91C614E527721A7A6F91EB364438AD3220CCA4FB103A445267C4FE5CCA6
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: expofreight.com
Sending IP: 185.222.58.101
From: expofreight <nipunag@expofreight.com>
Subject: Requesting for air freight charges
Attachment: Requesting for air freight charges.zip (contains "Requesting for air freight charges.exe")

Loki C2:
http://clemglobal.com/bobby2file/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-26 08:18:05 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip ce73931f25595f2897c8b959fb1080cbb48a6a14f1e3d3a1aefd0266195f919f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments