MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 933209274ed4f7eeb6884135bcab8a531f1447468e213dc8b2d8198c5c6b8de0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 933209274ed4f7eeb6884135bcab8a531f1447468e213dc8b2d8198c5c6b8de0
SHA3-384 hash: 451a8bcaf7f252bb4b9333186bb128a86c308ae3d2cfd9caf70a91c2c8ad3d702e23066cb60146cd02be512ff89d8e0f
SHA1 hash: 43f374c2230a703f0600579e30d99f6aad1547aa
MD5 hash: cfdd73ab74cd4c2bb170fd3addad6b67
humanhash: aspen-mars-friend-orange
File name:New PO#7597072020.r11
Download: download sample
Signature Loki
File size:25'126 bytes
First seen:2020-04-09 06:36:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:PBI6eDtaXIFmt00Gf2BOJcxUvliebfVKfjmQQEGMzVveWXF8YYhEeWbjQ1LWYVfn:5ZXIIcdfv4ebf0KQQE/VG3YYyQ1
TLSH F2B2E158BF2260B61932D13456A42D1983F3E5033A554FD4DFA2E08068ADEBF1E57A3B
Reporter cocaman
Tags:Loki r11

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-09 08:01:37 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
20 of 47 (42.55%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 933209274ed4f7eeb6884135bcab8a531f1447468e213dc8b2d8198c5c6b8de0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments