MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 248029edfe9d86c76173e4ac2823ed566d664c6020152b1f1748fbe971d16918. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 248029edfe9d86c76173e4ac2823ed566d664c6020152b1f1748fbe971d16918
SHA3-384 hash: 325e2b9769039dd50e1058874a9575cd712605c3decfc13c113fd05c1cda83b0811012b04b1eb243bab84ecfc9aa5800
SHA1 hash: c3d8e4b5d8d5e77e720c98a9c3a697acacb77110
MD5 hash: 4d0be487e155841b24b519cc18091765
humanhash: fanta-vegan-chicken-nineteen
File name:PO 210111-031.cab
Download: download sample
Signature Loki
File size:520'942 bytes
First seen:2021-01-11 09:04:00 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:gbUo3DEZc+p2Zp7RJYSDpKbW12HehzSOjito6h3VvFp:gRDqc+gZp7nT0bm2HehOOWjLdp
TLSH BEB42330EE95309245FA13B5B89A0E030B6B3144748E4DD9BE0CBE2BF96C6DC4DD7696
Reporter abuse_ch
Tags:cab geo KOR Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail-smail-vm47.hanmail.net
Sending IP: 203.133.180.235
From: 대진기계 <bosungyh@hanmail.net>
Subject: 견적 요청
Attachment: PO 210111-031.cab (contains "PO 210111-031.exe")

Loki C2:
http://79.124.8.6/plesk-site-preview/bosungind-kr.co/https/79.124.8.6/kiriko/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-01-11 06:40:48 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

cab 248029edfe9d86c76173e4ac2823ed566d664c6020152b1f1748fbe971d16918

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments