MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8abf8a5e71416f0939a52379f0fe6d91cf7ec97e58cda4c4d4b488e6a190444a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8abf8a5e71416f0939a52379f0fe6d91cf7ec97e58cda4c4d4b488e6a190444a
SHA3-384 hash: c87826de2c39cfbc27190146acfa0f7e31f98bdb8ddd840bedf41fc2aa2ac5a7f6d74a8f3c8f7d63c7ce7a3ec41564d2
SHA1 hash: 4bb6e4e354581b7f0118c3b60ae99ddaa6b9ef22
MD5 hash: 444fa79a883c46c86c888a25e621f183
humanhash: quiet-don-whiskey-delaware
File name:Scan_Doc_pdf.arj
Download: download sample
Signature Loki
File size:1'505'988 bytes
First seen:2020-05-06 09:57:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:CJsQqFDHyQZn0J99vqTyIgcknJ/xiORXu5k9EQR5HX74qR/Asp6GBJ2Et5vISRiu:CWQqJyQZ0FvqHg/Jpi8umuS4qR/Ag6oh
TLSH 6A6533013FCFF377925F8ECE341962D15B193FA6E2496338A25CA6A5BE1913F601A047
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.the1sthost.com
Sending IP: 94.130.69.112
From: sales@fantaziahotel.com
Subject: DUE TO COVID '19- NEW PURCHASE ORDER
Attachment: Scan_Doc_pdf.arj (contains "Scan_Doc_pdf.exe")

Loki C2:
http://aesseal-my.com/first/chief1/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-06 01:52:05 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
17 of 31 (54.84%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 8abf8a5e71416f0939a52379f0fe6d91cf7ec97e58cda4c4d4b488e6a190444a

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments