MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93980cc0f41159dba7bb33248c35f65e63c30f5f8ef92913c34dea88a45d93a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 93980cc0f41159dba7bb33248c35f65e63c30f5f8ef92913c34dea88a45d93a0
SHA3-384 hash: bdc241d81032e0036ffb46a3c041972858d126147443056274a5f6c61cc81afeea966c6c63cb3877c7d886f66d066ec1
SHA1 hash: 2d377a904dd9c156571707e5004d0f6f145700b5
MD5 hash: 8b3f306c4dc1fb79e7cf9bdcceb8552a
humanhash: nuts-bravo-rugby-chicken
File name:843647A263.pdf.zip
Download: download sample
Signature Loki
File size:483'357 bytes
First seen:2020-11-18 13:39:39 UTC
Last seen:2020-11-27 10:14:39 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:gWvPDh6U8Hqmp7+HP1Nx0HFciumniJWFkQG9ZLVBMkj1JS/:TvPDcnp+1SDumiukPbJBMKJi
TLSH 98A433DABCAEA5E1F89A16BC6315C466883EE08550C3EC5FEF355C108D9FAD1C3961C4
Reporter GovCERT_CH
Tags:Loki

Intelligence


File Origin
# of uploads :
32
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-11-17 23:50:18 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 93980cc0f41159dba7bb33248c35f65e63c30f5f8ef92913c34dea88a45d93a0

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments