MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ad12b4174ad7c518b7c735a00f504ec6439abc5687d19816886386db1bbdba4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1ad12b4174ad7c518b7c735a00f504ec6439abc5687d19816886386db1bbdba4
SHA3-384 hash: 37bd5c967cc63ed4ff878fcd4ac577280475a5583fdeb0b66e4d54938e5fb912de02e0aa767d4d217703b5901d7367ea
SHA1 hash: 5c28b909ecf67dbaf27e940caf18badecf81d966
MD5 hash: 315aee9010defe70b241559a86f8c5b6
humanhash: golf-seventeen-sad-solar
File name:SG00936Q0122322SGFE.GZ
Download: download sample
Signature Loki
File size:381'616 bytes
First seen:2020-08-19 14:45:04 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:uXoRY/+pvOyAdgOrH1OoGs/DGdFQcPHUYFP//6qC1N0kfw7dGeWmCj+2004Vejgg:4+O+pCg+OoGsL+PHvFP//6qyq7d9Wjjr
TLSH 008423628C9A089D65A6C0F78E0BFD36D3433B54B80EF915B1A623B5E1E9B4550E3C0E
Reporter abuse_ch
Tags:gz Loki SCB


Avatar
abuse_ch
Malspam distributing Loki:

HELO: empre10585.dedicados.cl
Sending IP: 201.148.105.85
From: Standard Chartered Bank <AdvicesSG@sc.com>
Subject: SUBJECT:Advice from Standard Chartered Bank
Attachment: SG00936Q0122322SGFE.GZ (contains "SG00936Q0122322SGFE.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-08-19 14:45:13 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 1ad12b4174ad7c518b7c735a00f504ec6439abc5687d19816886386db1bbdba4

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments