MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 559bcdc82d42294adceb6f6b268fee48cb2ee55e7ce1d163b1d581a708fdae69. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 18
| SHA256 hash: | 559bcdc82d42294adceb6f6b268fee48cb2ee55e7ce1d163b1d581a708fdae69 |
|---|---|
| SHA3-384 hash: | 9d82e83da66d2f89c2c7cb9c3541aa2e7e36864ff3cffc8a8f3376d3b48349a33107cabbcadf76fe1fdbb52a4d340c93 |
| SHA1 hash: | 27353281b11498375c7b61d1d77089242dd14222 |
| MD5 hash: | efb8b70d0ade09d402abae53484772c0 |
| humanhash: | sink-eighteen-kilo-kentucky |
| File name: | SKB STATEMENT JULY + SKB PACIFIC BANK SLIP 03.exe |
| Download: | download sample |
| Signature | Loki |
| File size: | 465'408 bytes |
| First seen: | 2023-08-03 20:55:14 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'647 x AgentTesla, 19'451 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 6144:dWvPb4ulWyjAxHPgNt+uQUE9y/gfNdELN1GDBc1fZYB5CY9mJG5py2V/8S/M842r:dq7UF4NtTQXxdE51uyu5Csmw5ZN/C5n |
| Threatray | 3'889 similar samples on MalwareBazaar |
| TLSH | T11FA422F036EE56F8CD9847B994D2548013694BD7A4E8FB3DAEC920945AC27063436F2F |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 5ab9f8e4f8999ab8 (5 x Loki, 5 x AgentTesla, 3 x Formbook) |
| Reporter | |
| Tags: | exe Loki |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
559bcdc82d42294adceb6f6b268fee48cb2ee55e7ce1d163b1d581a708fdae69
0fc20cce6837bf4c422edb29a17a139d282a036d9cb68abb1b8290a694dc8026
0b3086effd8f6fba603ce006970a17242a05c79e30acc38b61b50600558e27d6
c90bb9ff7894af79b5f98b328712d1d8817d8e941b1cf70805706902ed5a6457
41806b559cc3d4245a5e2caac6f1fcc88684f6a4efe33c0d7665e137f2864c96
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.