MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9c408d483d491c30a70941cdfcaf4ff0b05a0ee3d2c2d2fb95cf4ac4964e6c42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 14
| SHA256 hash: | 9c408d483d491c30a70941cdfcaf4ff0b05a0ee3d2c2d2fb95cf4ac4964e6c42 |
|---|---|
| SHA3-384 hash: | d34503ac0a09b5fa745bae995d77fb6ea485076f304ac45ca60f4f00fab4d75e8bc234028a1f9c0e8556f5e1533acb5b |
| SHA1 hash: | a01de7d98b8542a36e87cb3b55ccb8c6606be9d6 |
| MD5 hash: | a61ea583dca0f8b031a548a919a92a9b |
| humanhash: | failed-solar-emma-carpet |
| File name: | DHL Receipt_AWB#1603760504.exe |
| Download: | download sample |
| Signature | Loki |
| File size: | 516'096 bytes |
| First seen: | 2022-04-27 07:21:27 UTC |
| Last seen: | 2022-04-27 08:11:07 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'655 x AgentTesla, 19'464 x Formbook, 12'205 x SnakeKeylogger) |
| ssdeep | 12288:nV31pYI2FxLWJemi02OCBYgcmSYscmj3/:VH6QHi+dgrSYscm7/ |
| Threatray | 8'376 similar samples on MalwareBazaar |
| TLSH | T129B40134ABDC8F16C7BF5AB5E434421097F9DB2A7152EB9F9DC0A0E40C5678246123B7 |
| TrID | 49.6% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 21.2% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 8.9% (.SCR) Windows screen saver (13101/52/3) 7.1% (.EXE) Win64 Executable (generic) (10523/12/4) 4.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) |
| File icon (PE): | |
| dhash icon | 69dca0e8e8e0c448 (22 x AgentTesla, 8 x SnakeKeylogger, 6 x Loki) |
| Reporter | |
| Tags: | DHL exe Loki |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
702966eb365937eb195010449eb592a3817d74d0f7e4da14a0e9fbb13b5303b6
08106cb69541207153d2bf8e3d7719d43ad861d79bdd70558941582144ad2b91
9c408d483d491c30a70941cdfcaf4ff0b05a0ee3d2c2d2fb95cf4ac4964e6c42
b2110a378d750fec1151e3cda11fcd9633f2aac8a8899366714b420b44201acc
b93f0ee6a6465bd298f52ee913fc7bc56693cfa6e31dc1c13a3eb6c35c53b960
1aadfc0d778b0d7bb238840a64991ea77998ca45c480280ed3945ecd2d29649f
f000361a38df0b0599f682e97126ca3120f0261a8555e7bb03595152fdb7d4e1
7af4925ef23c08cc12eb4aa6822f8d46c01d829cc32462a55d23ffec0c7c6e11
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.