MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6419bcef1ff9ee42026ad627ca1012b6419c9aa0b2cb1fbc48214f1c7100278e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6419bcef1ff9ee42026ad627ca1012b6419c9aa0b2cb1fbc48214f1c7100278e
SHA3-384 hash: c6fb119031d38a591703b331e7d054e40943efc5beea8dafb2746c4d6958a800d9a0e773767a0cc375111bf45f13d506
SHA1 hash: 47e13c0b4268788a67690ad17b51b2e1d10b56f6
MD5 hash: 0443c3895c04972c9297bc9e24ed9bd8
humanhash: indigo-uniform-eleven-twelve
File name:image003.png.gz
Download: download sample
Signature Loki
File size:368'837 bytes
First seen:2020-10-27 09:20:25 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:PQKqwdqyU6GRQHh4rK6Fs+VeWtZ8VKcy76bQw18h1OOjQ2OHZw6Rqsc:PQKjv4nsCtZ8VKcy/w6jfOHZwiqsc
TLSH E87423B68950C71D056C355B18027CFEE359325A6332A07AF7EC2CA06B46904EFDE979
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: srv.atexniki.gr
Sending IP: 62.171.174.83
From: Jing Wang <jsjingwangnet@163.com>
Subject: RFQ: Sample Order
Attachment: image003.png.gz (contains "image003.exe")

Loki C2:
http://qataracfridgerepaire.com/wp-admin/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 6419bcef1ff9ee42026ad627ca1012b6419c9aa0b2cb1fbc48214f1c7100278e

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments