MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5acc7dbe71b72bd6d771892244c492d6c4a4b4dd138157dbbfa772b4cab7d7cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5acc7dbe71b72bd6d771892244c492d6c4a4b4dd138157dbbfa772b4cab7d7cb
SHA3-384 hash: b1684688b366be16127d17250133a998127511326e2d343c9d19710a46a100c1dd499505652015293ac16abd8116af0e
SHA1 hash: c7805bf554fa15553434f6e17a86d945f6e3fe5a
MD5 hash: adbe62532e3a22e065917e4487a9f3e8
humanhash: jupiter-sixteen-blossom-salami
File name:file.lzh
Download: download sample
Signature Loki
File size:304'218 bytes
First seen:2020-06-29 06:05:10 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:dqvVB2C0t5PATte7E/8sa2MbU58sZBEQx1LUbf3iGm8xdafTUKRlSO:YvVB2nLWte7sEc8sZBEQTLQfyGm8x6gq
TLSH 0E5423D298BDE487E02563E9E0B7E1100E1C4699DE790BEC04F0646E3F3D858EBEE556
Reporter abuse_ch
Tags:geo KOR Loki lzh


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail-smail-vm30.hanmail.net
Sending IP: 203.133.180.214
From: UTITECH <chungdukjk@daum.net>
Subject: 유티아이테크-발주서 송부의건
Attachment: file.lzh (contains "jekstb.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.PonyStealer
Status:
Malicious
First seen:
2020-06-29 06:07:04 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 5acc7dbe71b72bd6d771892244c492d6c4a4b4dd138157dbbfa772b4cab7d7cb

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments