MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fa379a6aa2289a1802e364dc940f38bde30aa6096376e901926c16a822eb591. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2fa379a6aa2289a1802e364dc940f38bde30aa6096376e901926c16a822eb591
SHA3-384 hash: 09fea80d6543d8a9570fee45e25937b014be9ac2f0775d717e7278511fac0faf0c8fa0090eaadda056a4a353b6e69cba
SHA1 hash: 66336741af2298be6d30ad68a10034cda0f4075e
MD5 hash: 176d62682de45ffa920eb0d8c01b0303
humanhash: whiskey-ceiling-lithium-burger
File name:Docs-Scan011105_pdf.arj
Download: download sample
Signature Loki
File size:370'238 bytes
First seen:2020-06-02 05:50:05 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:7qmoroVjCJPiueS2YuzvSNJ/i3T1rAQXIq//rpcioMpyWwA23Tjop2KO2JxzkvU6:7qmwoVjCJ0jcli35AQDtnDyWI3nk3OOw
TLSH 0F742302DA08F3A959245C07FD36FADBB77A2B1B1C6457C0876C81DCB44AA843E1A71F
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 01:51:00 UTC
File Type:
Binary (Archive)
Extracted files:
287
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 2fa379a6aa2289a1802e364dc940f38bde30aa6096376e901926c16a822eb591

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments