MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53f9e9aa91c6707ae8207d64c0a3fe2273b9ed05fa9905e90b709fa20baf8e94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53f9e9aa91c6707ae8207d64c0a3fe2273b9ed05fa9905e90b709fa20baf8e94
SHA3-384 hash: 3c1ae0bd245c8d7be5d9cef0c1ffaba22830099ea33af44b3819c076f60adbdf4ce85b4c079a782d83f491b94fd58df9
SHA1 hash: e2af77b36e86c24001aff3db75f8e9352dfb9d33
MD5 hash: 27a30d1ff70c5c5754f7d4b7b2b2fe9f
humanhash: purple-jupiter-pasta-wisconsin
File name:BL_COPY.exe
Download: download sample
Signature Loki
File size:1'183'744 bytes
First seen:2020-04-30 07:35:52 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2db07d6d98d3bdc12a8df4c5d53051a5 (1 x Loki)
ssdeep 3072:UgPqNYwuH6fY0uq6Cw6MaT26+Ie9yvgOyuvKoRbcx9jKoRbcx9Aw3NLCYgxpjBx8:U5ACw6p2ge9yIeKoKKoWNLCFpIoS
Threatray 52 similar samples on MalwareBazaar
TLSH EE459EF43ED17997C225907EAD128E08C7E458777B4DB862F357A60B12E07E19BE0923
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaSetSystemError
MSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaFileOpen
MSVBVM60.DLL::__vbaErrorOverflow

Comments