🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 95a0398e01cb92e17f1621dbcd9cbfbd280f7ff8f2004d15917ff80ef33338dc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments 1

SHA256 hash: 95a0398e01cb92e17f1621dbcd9cbfbd280f7ff8f2004d15917ff80ef33338dc
SHA3-384 hash: 560103d5345085faabd3be6ecf0663cdac87cba2e5949655ee96f4c1c51f3c31b660970a4adf43683da539794f168372
SHA1 hash: 5bce96ce82e8a30f99e90e456fd3d73c3e41596b
MD5 hash: f880c540e727cc53310961cd23aca196
humanhash: eight-saturn-artist-eighteen
File name:825B7A64DB82A61656C8004BEF49823D5B9FE4F52FAE744F5DC927B3E75A994B.7z
Download: download sample
Signature Loki
File size:184'986 bytes
First seen:2022-07-26 16:13:37 UTC
Last seen:2022-07-26 16:17:53 UTC
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 3072:yuzjJnOXTfp6aaCMQxixFEdeU6E+y6SUh1xK548HDndv/rKcPlrLUa24kE+F4JCL:BPNITElNAeHy6SUhsPDPlrLUmkEweCL
TLSH T1020423D3D7EF2D3572ED9925D80C874A2AA3681C52C843BF4EE61F46D54E70BE1A2704
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Reporter sarab
Tags:7z Loki Lokibot xls

Intelligence


File Origin
# of uploads :
2
# of downloads :
533
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
CVE-2018-0802 embedequation exploit shellcode VelvetSweatshop
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Launches Equation Editor
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

7z 95a0398e01cb92e17f1621dbcd9cbfbd280f7ff8f2004d15917ff80ef33338dc

(this sample)

  
Dropping
lokibot
  
Delivery method
Distributed via e-mail attachment

Comments



Avatar
Muhammad Hasan Ali commented on 2022-07-26 16:19:25 UTC

How should i upload a sample in correct way?