MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 28b12bda9284e159d3c3cba9dd11165b4e6e4ce6eb52ae79cbbdb12ad5d7048c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 16
| SHA256 hash: | 28b12bda9284e159d3c3cba9dd11165b4e6e4ce6eb52ae79cbbdb12ad5d7048c |
|---|---|
| SHA3-384 hash: | 7914a5d8f25d0f5cb7463631c36f7f60564d9e5907cefa8dfbcfcc65f0de9cad0c6819ac1338563444525605b7671eac |
| SHA1 hash: | ef69b4600c5e1b71dc888e75c8046df4e3393890 |
| MD5 hash: | 5d78364bf2437ae40cac58d917c7ef80 |
| humanhash: | single-whiskey-two-island |
| File name: | ClBaqN0PlVLXrhZ.exe |
| Download: | download sample |
| Signature | Loki |
| File size: | 1'049'088 bytes |
| First seen: | 2022-10-20 08:22:15 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'742 x AgentTesla, 19'607 x Formbook, 12'242 x SnakeKeylogger) |
| ssdeep | 24576:MxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxNussKD84GSb4:wZNXwlNcFdj |
| Threatray | 11'055 similar samples on MalwareBazaar |
| TLSH | T1F92507B922C0229FD426B1758193E9B362F77D226116D1CB50C30F6FBC486BBDA16397 |
| TrID | 64.2% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 11.5% (.SCR) Windows screen saver (13101/52/3) 9.2% (.EXE) Win64 Executable (generic) (10523/12/4) 5.7% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 3.9% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 1031ccc4ccccaa10 (14 x Loki, 12 x SnakeKeylogger, 11 x Formbook) |
| Reporter | |
| Tags: | exe Loki |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
35ab7d3f5ddf80aac8ac8ba5c4754ffcf047fbb664901eafb0a1fbfb360a33ef
302e773d3fa9a4c76f16cffaf1637ef8d25ac85a773ca37e4183a1c205f03b7f
ccffa2c388af2b3da210647b0f7be25a53cf7a4c6f99bf4b64987e881b763e23
28b12bda9284e159d3c3cba9dd11165b4e6e4ce6eb52ae79cbbdb12ad5d7048c
6fad980be503879043508f87004593ee8344b765157fe787cfef4d64bee02dab
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.