MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e0272d0db0605d5dc68dec1eb378a0144fd0a20ab13ec41f4f42f29a72767e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5e0272d0db0605d5dc68dec1eb378a0144fd0a20ab13ec41f4f42f29a72767e6
SHA3-384 hash: 1203b87b507294c2f25a5f21c6413fbe27dabf2611ab46b6af05752b2e863eb9182da93310f452728e4000a39891725f
SHA1 hash: 1f83db4cb41c1650c2c535786e58760e8dc98459
MD5 hash: 979ab7f99b0fe30aa5629fdff6aeea63
humanhash: whiskey-yankee-massachusetts-april
File name:LatePaymentAdvice.gz
Download: download sample
Signature Loki
File size:23'177 bytes
First seen:2020-05-14 04:53:08 UTC
Last seen:2020-05-14 09:02:16 UTC
File type: gz
MIME type:application/x-rar
ssdeep 384:UASZDaRFrj/Rzbkohx7nYnheStJwQ9wQMpDj+LDZPdw/MBIq91eCRMiPlftyel18:V+DaRFrjZzbk2VajJ3JMpmLV+sdOniPo
TLSH F8A2E1C926B2A73524E50F9B62D903A60AFACC194CCBAD4A77781431839BCE01FC74A5
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 05:35:35 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 5e0272d0db0605d5dc68dec1eb378a0144fd0a20ab13ec41f4f42f29a72767e6

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments