MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 828e3b1f2d646f988ba81f30ac47bda1e082a4a63735e1a87cb4e44db0514cdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 14
| SHA256 hash: | 828e3b1f2d646f988ba81f30ac47bda1e082a4a63735e1a87cb4e44db0514cdc |
|---|---|
| SHA3-384 hash: | b1c6003d3bad9ff316a5253311c76b10a9b8ad9cd355e20d0d1a55c90e379a002479731e2c218ac855b3ba996a8cb8a7 |
| SHA1 hash: | 87a0de1687805fc8b8ee673a16844c2a45d2b738 |
| MD5 hash: | f60ee0d806af50b985421504b2a6087f |
| humanhash: | music-xray-comet-bacon |
| File name: | Escanear copia001.pdf.exe |
| Download: | download sample |
| Signature | Loki |
| File size: | 798'208 bytes |
| First seen: | 2021-09-06 19:16:28 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger) |
| ssdeep | 6144:ZpgwDeFJLgGDeYHZgfbUR3YTvBby7xzlUo/1ijsMX6V0Ag18tB:DK5gfoYb9AziXj8t |
| Threatray | 5'094 similar samples on MalwareBazaar |
| TLSH | T13705EC3E18FE2327D166D7F5CBE0C823B2D09CAF3122A92457D75B665356A4634C322E |
| Reporter | |
| Tags: | exe Loki Lokibot |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
42dff3b3fb6effeeb3a6c4ff8049cc698689d3a2bcb4544931593374d9b43501
f6c80fd45ffb6d6410584e354b55caf6ae7657436db901384732bf9987058110
a7ab34d281786408a2a26a60f054b1ce757073f64f117a9bdc27b3717d4c4a50
cbf60d5f72e0b4d92f31512cfb3e6380e47bf50b8a600d763b2febff78425288
18167be6b99aefbe9432ccfa01f2adc573b89f501dd45d25e27051b45701af85
5af97bca353cf171403bc61a6aa544cbca796c0160f942388b56a66932b09b44
6ffa78774b2d87e1401cb4e2cc783597fab1666f19f25ce0dcdced717620000f
828e3b1f2d646f988ba81f30ac47bda1e082a4a63735e1a87cb4e44db0514cdc
711354645f542b5cf224ee40a69fd44eb099966e554be3f7916ee040a82bdc0f
ba05c469286b8eebcd354867cd1a44f0aaf0b5c8f8b48ff3d2081fa8192be9d4
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_SUSPICIOUS_Stomped_PECompilation_Timestamp_InTheFuture |
|---|---|
| Author: | ditekSHen |
| Description: | Detect executables with stomped PE compilation timestamp that is greater than local current time |
| Rule name: | pe_imphash |
|---|
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.