MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 03472b168c39e86f001b37a99508dc959a192ece8f14bfc1c66c8bb635c6122b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 03472b168c39e86f001b37a99508dc959a192ece8f14bfc1c66c8bb635c6122b |
|---|---|
| SHA3-384 hash: | 0801a660fb7f9924f4bab84bc529ce0d0a89638b12d1866032bafb60cd03bc2ff0592b65e00895786f09cf1f08862c92 |
| SHA1 hash: | f6c32b278dfd7c78c189012ab7b1a06683dc56d7 |
| MD5 hash: | 9b25dc9e4cfc4b4d6bcc10e646ff11f7 |
| humanhash: | football-fruit-massachusetts-high |
| File name: | Arrival Details_DOC_MEDUI1938022...._PDF.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 359'266 bytes |
| First seen: | 2020-10-12 14:58:56 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:Uz7st6ztr4iEI3sm3k+7Ice+ZWGd3wIRihVRcNtzdpvDQxRzjvQdWE1muhH7UlC:UX3raWD3k+75phwuCv8tDrQzSWqd7UU |
| TLSH | 72742334617533394D2722E9EECEA8937CCA237B5C071C6E8F69B2AB5B566483E44701 |
| Reporter | |
| Tags: | gz Loki |
abuse_ch
Malspam distributing Loki:HELO: server.devbox12.com
Sending IP: 162.249.2.44
From: Warren Smith <warren@airwaveaust.com.au>
Reply-To: Warren Smith <ricknicolas.aol@hotmail.com>
Subject: Arrival Notice of B/L#MEDUI1938022 on MSC VIVIANA/FT038E received
Attachment: Arrival Details_DOC_MEDUI1938022...._PDF.gz (contains "Arrival Details_DOC_MEDUI1938022...._PDF.exe")
Loki C2:
http://milonga-a-promotora.pt/wp778/Panel/fre.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.CryptInject
Status:
Malicious
First seen:
2020-10-12 12:19:11 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.