MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 172dd30973ca76e6558803011d610e83d4f2f66a79b04533c636aec32b065036. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 5
| SHA256 hash: | 172dd30973ca76e6558803011d610e83d4f2f66a79b04533c636aec32b065036 |
|---|---|
| SHA3-384 hash: | a2709fa70de59847890146f40683651aa3d8c37f6d3d8d84df0262aa4782731613d553391b03ef6209a51786ee51b1f4 |
| SHA1 hash: | 8fbf7e176b261dbbc0c0749aa8a70e5a0b5ea28a |
| MD5 hash: | 6eb1071fd99c8fa3f1ca838f090d0f07 |
| humanhash: | sixteen-cup-angel-summer |
| File name: | Spare RFQ-000090-1375 484969-0TQW6.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 701'087 bytes |
| First seen: | 2021-02-04 09:39:31 UTC |
| Last seen: | 2021-02-11 20:23:40 UTC |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:6zaoE9KMdC7GLVlLelWy6z12aMY1bq++qrfcfNtp4+MuAnL2WH1o4AuepiGo/9vU:UEIMdC7Gnrz12/YNHOy+MGWVHAun/9vU |
| TLSH | ACE42327C9F4DEE86F5EB7272347F33B145612AE2ADCA5B8A250D8500E478D256403BF |
| Reporter | |
| Tags: | Loki |
Intelligence
File Origin
# of uploads :
14
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-02-04 01:06:10 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropped by
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.