MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1bb8852c2f8f20cb1b80a61bbda5ebd241559e4c9992b8c2948ca5800151643b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1bb8852c2f8f20cb1b80a61bbda5ebd241559e4c9992b8c2948ca5800151643b
SHA3-384 hash: 66a9faa84ef5a67d91eeca1561a2e0fc632d4dc39d2beb10fe07dcdca012be6cc6e1d16305e6675bd9cf3b6cc714e839
SHA1 hash: c36f8bd62d829e0a4c6942abce4dbcd3f25bf01a
MD5 hash: 477e76ad89ccfe746882ca4abc402d39
humanhash: failed-april-quiet-delta
File name:COVID-19_UPDATE_PDF.7z
Download: download sample
Signature Loki
File size:332'640 bytes
First seen:2020-04-01 11:46:14 UTC
Last seen:2020-04-01 12:17:57 UTC
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 6144:XVwYjFvwjncDZ2nw1Oor55CA2zpbDg5NxAOvSdMYsxUgLv2N9Q7eCWlteQgpug9:CYjFv8cDZjEo+A2zlgXx/v2WUkmbCWl4
TLSH 55642349171DEE688842EAABB8F9D3B67D3F8E6FF71D0673101C828405EE97194F6124
Reporter abuse_ch
Tags:7z COVID-19 Loki


Avatar
abuse_ch
COVID-19 malspam distributing Loki:

HELO: slot0.farolexshippings.com
Sending IP: 185.70.107.206
From: Andrée Pinard Clark <who60@who.int>
Subject: COVID-19 UPDATE !!!
Attachment: COVID-19_UPDATE_PDF.7z (contains "COVID-19_UPDATE_PDF.exe")

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-01 12:35:44 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

7z 1bb8852c2f8f20cb1b80a61bbda5ebd241559e4c9992b8c2948ca5800151643b

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments