MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a2dd20ff88d3b7958adfef44c7e20c29c69ae0290b94e9450c75951e230dd63. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6a2dd20ff88d3b7958adfef44c7e20c29c69ae0290b94e9450c75951e230dd63
SHA3-384 hash: 7cc0f724a08143dd82954ba6ec12f795eefd5d2ea9476ec8867407714ddbadcb6296d67d7b81e2a0692dfb7aae9b8acb
SHA1 hash: 3178c5b86465d82880962774d6d8ca30a4f914b8
MD5 hash: b51e1d4df1b466850c9c9adfd18701d5
humanhash: pasta-dakota-oxygen-whiskey
File name:Purchase Order _pdf.gz
Download: download sample
Signature Loki
File size:152'229 bytes
First seen:2020-05-06 05:17:15 UTC
Last seen:2020-05-06 13:32:49 UTC
File type: zip
MIME type:application/zip
ssdeep 3072:JZQkTAOA/nI3hDtcGVt0WcuPNFzIZCiVrPyl3+S0FECE:J+kHanuDtv0WvPze9rc3j4E
TLSH 74E312DB949709A9C6B138129176E36E88E3121D0911DAC7EEF53C63276CC253DECD72
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
4
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Heye
Status:
Malicious
First seen:
2020-05-06 05:25:08 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 6a2dd20ff88d3b7958adfef44c7e20c29c69ae0290b94e9450c75951e230dd63

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments