MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46233f89de24bca60042450622149a3185b1684f1c8f3f23b8ae822dd7cd2347. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 46233f89de24bca60042450622149a3185b1684f1c8f3f23b8ae822dd7cd2347
SHA3-384 hash: 49f6c557512e2a1e8918afb28d0764a3ae190ef96a1926f252e53d008f5f5d5015d09f25cbba30940b12d9a5929566ad
SHA1 hash: 69b8e61d4bc4034abc7370641d2235b91cc16527
MD5 hash: d909bd8593bf92043f21436ab2d02f8b
humanhash: diet-nineteen-nineteen-sink
File name:W879O3475.gz
Download: download sample
Signature Loki
File size:351'271 bytes
First seen:2020-06-17 18:24:23 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Y+zKqg19Mx/mhHG+7bCy5EUrRRcJrC5kp4r41HsREb:ab1MqmGbjE8c9C6pDpz
TLSH 887423EB025650B439DFDE094F8340EAEA5FAC37858C4CD98D13076A45D666B3E2DCE2
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mgabilisim.com
Sending IP: 185.78.85.242
From: Commercial manager <liufang@sinoma-ncdri.cn>
Subject: RE: New Order Booking/
Attachment: W879O3475.gz (contains "W879O3475.exe")

Loki C2:
http://beesco.net/osama/osama2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 46233f89de24bca60042450622149a3185b1684f1c8f3f23b8ae822dd7cd2347

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments