MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e46b05139f79f4e6f34c513c4b168cfa649ac312816aa75cf37002d2c7405a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 6e46b05139f79f4e6f34c513c4b168cfa649ac312816aa75cf37002d2c7405a2
SHA3-384 hash: 68b6db086aba77511c32e78da3d39e36be9ae212277005d28171238179dbbf719920e76404705994d28a8e49205828a7
SHA1 hash: e0922699c65e6a52ecf3eea774653d8f3f0eb056
MD5 hash: dabd7a706c793aba86f0ff823e4e0fa7
humanhash: summer-hotel-moon-colorado
File name:file
Download: download sample
Signature Loki
File size:316'957 bytes
First seen:2020-05-26 11:05:05 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:QTBJ4l/QomhsGPP2nXdX0VEVX8nmfLn7tL/UoCVIDtmM6E5KGjAmW:iktPmhsKPs0VEWCnZcatmM6E5KkAF
TLSH 0B6423BE8F673249AA2F181DC552874636F7A5C7641CFD66E91BC28346EC12630BC4F2
Reporter abuse_ch
Tags:file Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail001.datapar.com
Sending IP: 170.238.19.37
From: Выставка WorldFood Moscow <nye@seve.gr>
Subject: ПОДВЕСКА МИРОВОЙ ПИЩЕВОЙ МОСКОВСКОЙ ВЫСТАВКИ
Attachment: file (contains "file.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-26 11:36:58 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 6e46b05139f79f4e6f34c513c4b168cfa649ac312816aa75cf37002d2c7405a2

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments