MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 244b479bd0336d465f025178dfdc57247abac4647f61ab34d6ea2b53ff7485ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 3
| SHA256 hash: | 244b479bd0336d465f025178dfdc57247abac4647f61ab34d6ea2b53ff7485ce |
|---|---|
| SHA3-384 hash: | 15b876ce1cb0f9ea16a6623f46fdeec6471629a9245829998290af7f668b1505f3674c110f240bd94dd3e7d94d78020c |
| SHA1 hash: | d36e52971c5cd36ca8c97e8157bc5c59e263974b |
| MD5 hash: | 0e7ff58c0e7bb273b25594f472bc1d94 |
| humanhash: | lithium-alpha-triple-mars |
| File name: | Oznámenie o platbe - Euro Bank EFG.r13 |
| Download: | download sample |
| Signature | Loki |
| File size: | 557'901 bytes |
| First seen: | 2021-01-19 12:56:10 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:o9DVHrMqgOdP8inypakl/ljOh4yOH5sC3C0e:MDVHwqbdP8dPlNoo5sd0e |
| TLSH | 36C423D4458D8A90C523F8AC5C9ABBAAF2397187143DECE5ADC38370293BD6F911C2D5 |
| Reporter | |
| Tags: | geo Loki r13 SVK |
abuse_ch
Malspam distributing Loki:HELO: zephir.ph
Sending IP: 45.137.22.41
From: ÚČTY / ANCHELÉN <info@zephir.ph>
Subject: Oznámenie o platbe - Euro Bank EFG
Attachment: Oznámenie o platbe - Euro Bank EFG.r13 (contains "Oznámenie o platbe - Euro Bank EFG.exe")
Loki C2:
http://becharnise.ir/fa2/fre.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
159
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-01-19 12:57:04 UTC
AV detection:
12 of 46 (26.09%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.