MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ac74de16ff50b09a8515802066c11e70c55ee2ade4eac341a92c34e477488e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6ac74de16ff50b09a8515802066c11e70c55ee2ade4eac341a92c34e477488e5
SHA3-384 hash: d4067c465ae81cb624f6e8f4af9fe6b4ab53cadd3e6c92fd0500663d052aac1f5d2c3a1d554fb14ed32da16238f337e6
SHA1 hash: 1e7974e6155775fd7287973b500e9e6c900c8d14
MD5 hash: 6a86541487bbe271b322e89c429a268c
humanhash: network-enemy-muppet-hawaii
File name:Bank Details.xlsx.zip
Download: download sample
Signature Loki
File size:217'969 bytes
First seen:2020-06-25 08:47:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:4eFB+WAMWJsup2FIRZBMFqOL//8bEVCgrsdB8Ips:4YB+WFwA4E4O78bfRQ
TLSH 67242357E7D04673613EE5228C9ECD2D8C600AEB04E6FA68F84C8242E47D8C59E6D77D
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: cun23.com
Sending IP: 45.127.62.110
From: antonio@mendenhall.gq
Subject: PAYMENT TO NEW BANK DETAILS (CONFIRM BANK DETAILS)
Attachment: Bank Details.xlsx.zip (contains "Payment Copy.exe")

Loki C2:
http://beckhoff-th.com/kon/kon2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 6ac74de16ff50b09a8515802066c11e70c55ee2ade4eac341a92c34e477488e5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments