MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bce4761977786a9d7ae6e5c9660204d648d3bc11bf1466fcb1b0bfbae0aade7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2bce4761977786a9d7ae6e5c9660204d648d3bc11bf1466fcb1b0bfbae0aade7
SHA3-384 hash: 414d7cbdbf88dd13b622dfb0a80bf808a7d87e101c44b51d5a5c072305885746b304e0010b9c95434b997e1439feb210
SHA1 hash: 4cad6ea026a666cef1fa6f48ab9666cbb40b22e9
MD5 hash: 83b81c333ed88dcfed259a9321043ab5
humanhash: aspen-spaghetti-spaghetti-solar
File name:Shipping docs024916.pdf.arj
Download: download sample
Signature Loki
File size:724'996 bytes
First seen:2020-05-12 06:24:34 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 12288:r9fsAd1pQaDoEb+sGr0KjIQgO5RPHY+If1F45D5yoLUZX+JF:rvJQaDo7srggORfQfD42pZX+JF
TLSH 98F4230FF02C5F1B06A2D87EAAF1303F2954670E6A0E53A9C6741B7F9555522A322DFC
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: host.webhostingz.in
Sending IP: 67.222.18.82
From: JAGUAR LOGISTICS CO.,LTD. <James@jaguarlog.com>
Subject: RE: TOP TOP URGENT!! REVISED SCAN SHIPMENT DOCS // MV. TAHO EUROPE
Attachment: Shipping docs024916.pdf.arj (contains "Shipping docs024916_pdf.exe")

Loki C2:
http://zangs.ga/choolee/gate.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-12 06:35:59 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

arj 2bce4761977786a9d7ae6e5c9660204d648d3bc11bf1466fcb1b0bfbae0aade7

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments