MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 94a011d3715943d4dc6a7c1007c698e321b148af545d6a72775a6e70d618a0fb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 94a011d3715943d4dc6a7c1007c698e321b148af545d6a72775a6e70d618a0fb
SHA3-384 hash: 837aea4bd4a60ffd6862ea1dcfa4610ddd88a99562b8b87315bd9c26380bf21743b72096df5bebfbb87cbcbd58eb63b1
SHA1 hash: 2e45f00a5ec453900dd915e87f2ac49cbb7ef4ed
MD5 hash: f3d7235ac87d4185a3fd7f8264876d04
humanhash: floor-hydrogen-iowa-oranges
File name:Scan_new_doc_1011_pdf.gz
Download: download sample
Signature Loki
File size:392'355 bytes
First seen:2020-05-07 06:02:50 UTC
Last seen:2020-05-07 10:19:38 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:Z6w3W3rawEDCKuEKyDApcX7CwchzrMGrSn96EdVdzkBs/Z3ivQmW70neGdU+jJqU:Z6Vr3EyEKOTfchg96UjZ3iImANGdlvOc
TLSH 228423D6A664E4B535C1CC241013B88EB7B1351BCA9AFD2C1D4F8EEB8612DE59371CB4
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-07 03:58:29 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
25 of 31 (80.65%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 94a011d3715943d4dc6a7c1007c698e321b148af545d6a72775a6e70d618a0fb

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments