MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25dfb97acd58972c16651dd37ec5df5c6b342332d446e1b0c4b5c883a24c626d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 25dfb97acd58972c16651dd37ec5df5c6b342332d446e1b0c4b5c883a24c626d
SHA3-384 hash: fd879bcd292e07517b364a10fa3ea82173060706aef97a2bbc3fc281d515eab6d6002174649f5a04678bc251ce0c42ea
SHA1 hash: 02906cba9c92920b524a747c22ba8d9869fba209
MD5 hash: 839bc8b52f1abe7da312e3365b8cdb7c
humanhash: blossom-maryland-mississippi-tennessee
File name:New Purchase Order DOC.gz
Download: download sample
Signature Loki
File size:446'580 bytes
First seen:2020-06-24 05:43:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:ShALOF25dS2rASUjLaik15rxxqq5ppPKmu:ShALOFmcWvMaiMTxPc
TLSH 4794235EACF8EBFF20B2D13F866611DF98A8797080A4885F0CDDD841D3926066A51DCF
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail.geveresintl.ga
Sending IP: 185.94.191.33
From: josh@geveresintl.ga
Subject: Re: New Purchase Order and BL
Attachment: New Purchase Order DOC.gz (contains "New Purchase Order DOC.exe")

Loki C2:
http://137.74.86.140/workabroad/logs/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Pws
Status:
Malicious
First seen:
2020-06-24 05:45:05 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 25dfb97acd58972c16651dd37ec5df5c6b342332d446e1b0c4b5c883a24c626d

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments