MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 98074087cbf7d034d68f98107162f2285775976e0c9d30957b7b03361cd91c53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 3
| SHA256 hash: | 98074087cbf7d034d68f98107162f2285775976e0c9d30957b7b03361cd91c53 |
|---|---|
| SHA3-384 hash: | 407f19be8dfffbfbd4a3b4ab3230c8cead6cfc1d5da7e52f8786d6f57c49e357d3c006790ad6c7db2dd92abfb2824800 |
| SHA1 hash: | d726f6158a075da0c96bff8171f7380cff21729c |
| MD5 hash: | 50345320eedfa66e2bc567c928898b18 |
| humanhash: | magnesium-blue-violet-salami |
| File name: | ΑΙΤΗΣΗ ΓΙΑ ΠΡΟΣΦΟΡΑ 21-01-2021.rar |
| Download: | download sample |
| Signature | Loki |
| File size: | 214'620 bytes |
| First seen: | 2021-01-19 12:54:45 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 3072:6NICgrkhotIsxBikbza5wVSK+PjKZYQCrZBrLUCqptwv1DRYx28x3vn9Zvr:MNgrkU2kx5+LKgvapENRYI8hvjr |
| TLSH | 54242316254C67E7C44927E798AE740EA3EA5FCE6DAB94F49EC3612C1240CFC8FD0295 |
| Reporter | |
| Tags: | geo GRC Loki rar |
abuse_ch
Malspam distributing Loki:HELO: cloudhost-2060988.uk-south-2.nxcli.net
Sending IP: 165.84.218.167
From: Αριστοτέλειο Πανεπιστήμιο Θεσσαλονίκης <webmaster@auth.gr>
Subject: ΑΙΤΗΣΗ ΓΙΑ ΠΡΟΣΦΟΡΑ (Αριστοτέλειο Πανεπιστήμιο Θεσσαλονίκης) EUI894/GR4633
Attachment: ΑΙΤΗΣΗ ΓΙΑ ΠΡΟΣΦΟΡΑ 21-01-2021.rar (contains "ΑΙΤΗΣΗ ΓΙΑ ΠΡΟΣΦΟΡΑ 21-01-2021.exe")
Loki C2:
http://51.195.53.221/p.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
143
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Spyware.Noon
Status:
Malicious
First seen:
2021-01-19 12:55:08 UTC
AV detection:
11 of 44 (25.00%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.