MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82c72cf2ef33f2cd94fb2497ad48ee284e2aa5df4af83e9cc04f6f18c78e6b08. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 82c72cf2ef33f2cd94fb2497ad48ee284e2aa5df4af83e9cc04f6f18c78e6b08
SHA3-384 hash: a15bb661f7b79e06675a3f318427cefb104969fc274e399843874d3d75f2e8a5ad76311fc03b95b068329562f14d156a
SHA1 hash: cb5c49df1130a80bfa783bf3e650ade0f265a3fb
MD5 hash: d6ee084cff9bdfd5131c54b24210b585
humanhash: leopard-zulu-autumn-spring
File name:SCAN32568980.gz
Download: download sample
Signature Loki
File size:343'160 bytes
First seen:2020-06-26 08:12:31 UTC
Last seen:2020-06-26 08:49:34 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:gp9Pn4JZGShukuLMgFNBlPYw98xiryEpnZtmFTbQpOL1je5Lz7e+Zg/:i9P47dhI7CxzEpnZgV8EC5LPev/
TLSH 77742382E132F279992143ED6219C92D53ED2EED8BE255CDA61C2793394819BC1FD0CF
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: upg.adnslhosting.com
Sending IP: 198.15.82.214
From: Leo Wang <leowang@gtighl.com.cn>
Subject: FW:shipping document//BL,DN//765443323/
Attachment: SCAN32568980.gz (contains "SCAN32568980.exe")

Loki C2:
http://beesco.net/osama/osama2/fre.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-26 08:14:06 UTC
AV detection:
36 of 48 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 82c72cf2ef33f2cd94fb2497ad48ee284e2aa5df4af83e9cc04f6f18c78e6b08

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments