🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28
SHA3-384 hash: 86880ba5567bb505a9d2b279faf28ad6a5237151864a0119d0b9ef39187416356800402a866986073010bd7830337a6b
SHA1 hash: 43f800228bf4401a06ad271470ac7f415eccc864
MD5 hash: 473e05acc6195bf707b34546e23d31ed
humanhash: south-red-vermont-hot
File name:Rzxfenjk.exe
Download: download sample
Signature Loki
File size:862'464 bytes
First seen:2021-01-22 11:11:14 UTC
Last seen:2021-01-22 13:07:44 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 1725a6125dace753197d80a0d28262db (1 x Loki)
ssdeep 12288:dbtCM55UcR6nwT2KPU69ffadHe/+kOzR4iSRZ0zJLpVdXD16m9MQJiomEK:dZlSnwTX1WHkldiW+JpVUQJ/K
Threatray 14 similar samples on MalwareBazaar
TLSH E7057D22F2915433D1331A389F5B92F99D2DBF10BA6898466BF53D4CBF356813839293
Reporter ffforward
Tags:exe Loki Lokibot

Intelligence


File Origin
# of uploads :
2
# of downloads :
702
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
43f800228bf4401a06ad271470ac7f415eccc864.exe
Verdict:
Malicious activity
Analysis date:
2021-01-22 10:51:08 UTC
Tags:
trojan lokibot stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
DNS request
Sending a custom TCP request
Creating a file
Sending a UDP request
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
56 / 100
Signature
Contains functionality to detect sleep reduction / modifications
Machine Learning detection for sample
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2021-01-22 11:12:08 UTC
AV detection:
14 of 27 (51.85%)
Threat level:
  5/5
Result
Malware family:
modiloader
Score:
  10/10
Tags:
family:modiloader
Behaviour
Modifies system certificate store
Script User-Agent
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28
MD5 hash:
473e05acc6195bf707b34546e23d31ed
SHA1 hash:
43f800228bf4401a06ad271470ac7f415eccc864
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

Executable exe 73fccc2e9290fb5baad4bee3010ebc2835cbeb4fe35da0a822e2fd9793e2ad28

(this sample)

Comments