MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3219008f58a2f587d4d0dba5ddd3ca9a067014292967573885768c7fd4ca4758. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3219008f58a2f587d4d0dba5ddd3ca9a067014292967573885768c7fd4ca4758
SHA3-384 hash: 5de5067af29f3ac07a03763035265da922655d6c9e37474694b3a8700f0afd1d2c3e8f7e75447108146a362a52357edb
SHA1 hash: 8426a2139dd97f60ad96bfef9e269a085437c11c
MD5 hash: 1aa4ef645c326cb23364c0307817ffcc
humanhash: connecticut-ceiling-jig-alabama
File name:PO 200408-302A.cab
Download: download sample
Signature Loki
File size:533'981 bytes
First seen:2020-08-04 10:16:03 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:D7p6sW8JSuOH7C9nHBZig92lQLwNYuc+lGVO0Rw1g:Ogpg7C9GgQ/4+lGVO0y6
TLSH 99B4237C5803FF836E425E351EAD3D0AC55E8C3856F0E68A71728A4E067578BAF4DA84
Reporter abuse_ch
Tags:cab geo KOR Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail-smail-vm89.hanmail.net
Sending IP: 211.231.106.164
From: (주)다스코 구매팀 과장 신성민 <led-world@daum.net>
Subject: 긴급 구매 주문서
Attachment: PO 200408-302A.cab (contains "PO 200408-302A.exe")

Loki C2:
http://79.124.8.8/plesk-site-preview/krockabread.com/http/79.124.8.8/kiriko/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-04 10:17:08 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

cab 3219008f58a2f587d4d0dba5ddd3ca9a067014292967573885768c7fd4ca4758

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments