MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 2 File information 4 Yara Comments

SHA256 hash: 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f
SHA3-384 hash: 86f1bcee26cd064f6c35e83fa14ceaa8e26534d60884bd4299736d36d7c822eb8e06969fcd40fe115ea6bc4bd8232240
SHA1 hash: c487d9337e50d2ecfbfb1eb7771df38a54fd1164
MD5 hash: 4a2565717bc8326de771a970593c1194
humanhash: green-charlie-football-kitten
File name:RFQ scope of requirements..gz
Download: download sample
Signature Loki
File size:348'855 bytes
First seen:2020-06-30 12:43:51 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:wTXgvwQF7FZOONDDN7gOe93rl02/tSFPYMO1/WPl8Mp6r6JnEH5sRQgYWfaW3UeI:wTQ4OEsDB7bA3REJNRtF6r6JnSQ3UMh0
TLSH FF742312E65D9C93E31012D8C91E7CFE796FAED4ABCA558CB50518FFB46C9B36023209
Reporter @abuse_ch
Tags:gz Loki


Twitter
@abuse_ch
Malspam distributing Loki:

HELO: navmailsrv.navayuga.com
Sending IP: 207.244.65.197
From: Bader J. Al-Hajeri <info@traxconsulting.com>
Reply-To: Trax@consultant.com
Subject: Request For Commercial Offer.
Attachment: RFQ scope of requirements..gz (contains "gunzipped")

Intelligence


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 25
Origin country US US
ClamAV SecuriteInfo.com.Win32.Herz.B.23927.UNOFFICIAL
PUA.Win.Adware.Slugin-6803969-0
PUA.Win.Adware.Slugin-6840354-0
SecuriteInfo.com.Variant.Zusy.307895.13627.19246.UNOFFICIAL
CERT.PL MWDB Detection:n/a
Link: https://mwdb.cert.pl/sample/7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f/
ReversingLabs :Status:Malicious
Threat name:Win32.Trojan.Injector
First seen:2020-06-30 12:45:06 UTC
AV detection:22 of 48 (45.83%)
Threat level:   2/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 33.90%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments