MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3219008f58a2f587d4d0dba5ddd3ca9a067014292967573885768c7fd4ca4758. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 3219008f58a2f587d4d0dba5ddd3ca9a067014292967573885768c7fd4ca4758 |
|---|---|
| SHA3-384 hash: | 5de5067af29f3ac07a03763035265da922655d6c9e37474694b3a8700f0afd1d2c3e8f7e75447108146a362a52357edb |
| SHA1 hash: | 8426a2139dd97f60ad96bfef9e269a085437c11c |
| MD5 hash: | 1aa4ef645c326cb23364c0307817ffcc |
| humanhash: | connecticut-ceiling-jig-alabama |
| File name: | PO 200408-302A.cab |
| Download: | download sample |
| Signature | Loki |
| File size: | 533'981 bytes |
| First seen: | 2020-08-04 10:16:03 UTC |
| Last seen: | Never |
| File type: | cab |
| MIME type: | application/vnd.ms-cab-compressed |
| ssdeep | 12288:D7p6sW8JSuOH7C9nHBZig92lQLwNYuc+lGVO0Rw1g:Ogpg7C9GgQ/4+lGVO0y6 |
| TLSH | 99B4237C5803FF836E425E351EAD3D0AC55E8C3856F0E68A71728A4E067578BAF4DA84 |
| Reporter | |
| Tags: | cab geo KOR Loki |
abuse_ch
Malspam distributing Loki:HELO: mail-smail-vm89.hanmail.net
Sending IP: 211.231.106.164
From: (주)다스코 구매팀 과장 신성민 <led-world@daum.net>
Subject: 긴급 구매 주문서
Attachment: PO 200408-302A.cab (contains "PO 200408-302A.exe")
Loki C2:
http://79.124.8.8/plesk-site-preview/krockabread.com/http/79.124.8.8/kiriko/Panel/fre.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-08-04 10:17:08 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.