MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3181afe45923233c3d0ae445efaee0b3a514b735aa30cee651217166af134bc2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3181afe45923233c3d0ae445efaee0b3a514b735aa30cee651217166af134bc2
SHA3-384 hash: ba2e0534611a339c4034716df151480cf6c5e5c922c2c0745caadd02a1b5f7e2b077f3429f1be10b32ae50adc4d79747
SHA1 hash: 1da829981838f4c760032b8bea514cc8f3a86c9c
MD5 hash: aad6721310534fa135c0dc998faf60ac
humanhash: north-mars-maine-gee
File name:REQUEST FOR QUOTATION.arj
Download: download sample
Signature Loki
File size:324'288 bytes
First seen:2020-08-13 13:58:46 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:3QAL3yHIP+oEqaIOZSQfGCSUqTYn0bfNKXbsXdP+jjXzRjvzI2Ad4MEjk:3QADfXzOsESUq3bfoLssf9zIp4W
TLSH 6F6423301961EE343AFF051455AA6367A7F7AE867F68F7DC737A47C3B8183096068049
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: abuilyas.co.om
Sending IP: 95.211.208.25
From: Nicole tsai <navin@abuilyas.co.om>
Subject: URGENT REQUEST FOR QUOTATION
Attachment: REQUEST FOR QUOTATION.arj (contains "REQUEST FOR QUOTATION.exe")

Loki C2:
http://mecharnise.ir/ea12/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-08-13 14:00:07 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

arj 3181afe45923233c3d0ae445efaee0b3a514b735aa30cee651217166af134bc2

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments