MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 244b479bd0336d465f025178dfdc57247abac4647f61ab34d6ea2b53ff7485ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 244b479bd0336d465f025178dfdc57247abac4647f61ab34d6ea2b53ff7485ce
SHA3-384 hash: 15b876ce1cb0f9ea16a6623f46fdeec6471629a9245829998290af7f668b1505f3674c110f240bd94dd3e7d94d78020c
SHA1 hash: d36e52971c5cd36ca8c97e8157bc5c59e263974b
MD5 hash: 0e7ff58c0e7bb273b25594f472bc1d94
humanhash: lithium-alpha-triple-mars
File name:Oznámenie o platbe - Euro Bank EFG.r13
Download: download sample
Signature Loki
File size:557'901 bytes
First seen:2021-01-19 12:56:10 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:o9DVHrMqgOdP8inypakl/ljOh4yOH5sC3C0e:MDVHwqbdP8dPlNoo5sd0e
TLSH 36C423D4458D8A90C523F8AC5C9ABBAAF2397187143DECE5ADC38370293BD6F911C2D5
Reporter abuse_ch
Tags:geo Loki r13 SVK


Avatar
abuse_ch
Malspam distributing Loki:

HELO: zephir.ph
Sending IP: 45.137.22.41
From: ÚČTY / ANCHELÉN <info@zephir.ph>
Subject: Oznámenie o platbe - Euro Bank EFG
Attachment: Oznámenie o platbe - Euro Bank EFG.r13 (contains "Oznámenie o platbe - Euro Bank EFG.exe")

Loki C2:
http://becharnise.ir/fa2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-19 12:57:04 UTC
AV detection:
12 of 46 (26.09%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 244b479bd0336d465f025178dfdc57247abac4647f61ab34d6ea2b53ff7485ce

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments