MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7eed91e97a5f6d0fd18e45853ac2397849aaaba801354da690650e2457843f06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 7eed91e97a5f6d0fd18e45853ac2397849aaaba801354da690650e2457843f06
SHA3-384 hash: b059a17383a1a98a01c03882cb6daadda3f2835b1140451de5b2a985f49b1c4f14a98ac33d3b6004a8ff8884c351d676
SHA1 hash: 897262bcde2bdee723f21d7f812b2e10e535e4cc
MD5 hash: 0d002e72656d5098fe854b4de64fb307
humanhash: paris-chicken-enemy-double
File name:PO 874296.img
Download: download sample
Signature Loki
File size:628'736 bytes
First seen:2021-11-01 11:03:40 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:uXaoPrbzqhcbzLa4NQDOYyTjTtmJzOHZ+vuJkyxnTBcvu:uJrqhc/DuDJ+ssHguzTa
TLSH T1DFD49D2C3798B79ACAA91F7588230688A3F1D4433B32F35F65C855D82D21B16CB2F657
Reporter cocaman
Tags:img Loki


Avatar
cocaman
Malicious email (T1566.001)
From: "Andrew Clay <support@omaralfarouq.com>" (likely spoofed)
Received: "from 31-24-230-87.plesk.page (unknown [31.24.230.87]) "
Date: "Mon, 1 Nov 2021 06:48:34 +0000"
Subject: "Purchase Order for Office Supply"
Attachment: "PO 874296.img"

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated packed
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2021-11-01 11:04:06 UTC
AV detection:
19 of 45 (42.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

img 7eed91e97a5f6d0fd18e45853ac2397849aaaba801354da690650e2457843f06

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments