MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40bad13aa551f576bfd822daaeb2821cbf6985202d3b27b9ee31ea6b2c6919ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 40bad13aa551f576bfd822daaeb2821cbf6985202d3b27b9ee31ea6b2c6919ee
SHA3-384 hash: 66b660f9841364fbfa45e4a48cab8a8873740d8740f6ac33a9b3765090f41b21b3f2f86c6606ed684d6b43d70a3533cf
SHA1 hash: 6327b3e0a46d9d30ca1c828daedcfdc471773444
MD5 hash: c4dc81b070813ba458bc5e816532a962
humanhash: iowa-butter-xray-vermont
File name:rfq3076h.pdf.zip
Download: download sample
Signature Loki
File size:328'308 bytes
First seen:2020-06-10 17:48:02 UTC
Last seen:2020-06-11 05:26:00 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:cJSvnJhGhFvZYN6Htgn27kd1k7swwsKurlTGc3gZDJbnEkz4LmjmAn:cI+Wn8kQI0HgZVb/IOn
TLSH C36423308BA46483715CEAF96203FA4CD6DE0448C5889FCE5ADBB42BF175885DE3B613
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: plethico.com
Sending IP: 156.96.47.116
From: Goran skimic<amol@plethico.com>
Reply-To: Goran skimic<amnol@plethico.com>
Subject: revised product enquiry june rfq3076h
Attachment: rfq3076h.pdf.zip (contains "rfq3076h.pdf.exe")

Loki C2:
http://irangoodshop.com/nop/fre.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-10 17:40:29 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 40bad13aa551f576bfd822daaeb2821cbf6985202d3b27b9ee31ea6b2c6919ee

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments