MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 03541ffcb574dd73c84c4c3b3522225f03862123877b278e97e7a508586382b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 14
| SHA256 hash: | 03541ffcb574dd73c84c4c3b3522225f03862123877b278e97e7a508586382b2 |
|---|---|
| SHA3-384 hash: | d4b44b8da9d75672107510f8848e11573b2f282a6cf0ecf27747d2dcb7f523310b1d1d32e75f574d429ea7bdf558405a |
| SHA1 hash: | 07637ef666a806a822b64483a18c8c72a0124119 |
| MD5 hash: | baeaad7c8f71c3416063985b3eb90d82 |
| humanhash: | tennessee-network-spring-summer |
| File name: | BHT inquiry Ref Nr.520325310307.pdf.exe |
| Download: | download sample |
| Signature | Loki |
| File size: | 145'920 bytes |
| First seen: | 2023-10-04 16:29:02 UTC |
| Last seen: | 2023-10-09 11:32:32 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'657 x AgentTesla, 19'468 x Formbook, 12'206 x SnakeKeylogger) |
| ssdeep | 3072:wSvTqhg5w1T1AbV2BrNwkaNHQKvIiEqiiY4AAL7GmCMY7pdkG:wSW1TcqKkaFprrM |
| Threatray | 1 similar samples on MalwareBazaar |
| TLSH | T198E3F15AD79B81D1DCAAA7B095330F792F26DD6BA91305C43584332A4C7238684BFE0F |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 00be8323b233bac0 (79 x AgentTesla, 11 x Loki, 9 x DarkCloud) |
| Reporter | |
| Tags: | exe Loki |
Intelligence
File Origin
DEVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
6648d6be85d4611f71fb27b7598df56516c433bfe8fd51a1069bfbf1c8be0c29
b06c31ca5664c7f9142039d5a2e4f5201404d08e4d233b594e6e69cb4e1219a5
bdd8bc8cc85047d7ea0a4086a3fcfc1bd9f2f98794d50be234249b1a7e8ee1a6
03541ffcb574dd73c84c4c3b3522225f03862123877b278e97e7a508586382b2
d678f42c6c3a37927a20a466df089d70ea6e97e19888bf75db2a1da1a28710ed
91bff23f123fb307a7baebb69281c6d17f65fc7d3c7891bbbe7df3b486e4d10c
d1c7c7eb0ee2cada6ee4193a967c1c3c3f15a0fb73c9e5d0ff576088553737ae
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_EXE_Packed_ConfuserEx |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables packed with ConfuserEx Mod |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.