MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9dec2e1908b5f89bf52d119eba97a910bfdbd9b1e8ceda59d0a45e8aea9ee363. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9dec2e1908b5f89bf52d119eba97a910bfdbd9b1e8ceda59d0a45e8aea9ee363
SHA3-384 hash: 3fae06e687a138dda452076f9981639fc75a24ac15a45cec422ed83ae7824615064aad65610d634cadbfecbbd997cbc7
SHA1 hash: 43960de0c9d8e84c008cff90e5049ab42fe6016f
MD5 hash: 820bcca6baed05dfafcfa7e1eff607b2
humanhash: neptune-seventeen-oven-glucose
File name:Copy-510wgsytruy_pdf.gz
Download: download sample
Signature Loki
File size:350'298 bytes
First seen:2020-05-11 07:13:37 UTC
Last seen:2020-05-11 11:12:39 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:XJs+TMdLz+4vJh51EnohR5L2CpiEZ/Q1eMk+5u/UYMOJip86Z8o:XTDGlEogCppw/5aHHGt9
TLSH 2D7423C8D1D934295F3860EB9BE2CFBDCA4F3F85605CE50420EF462ECB29A79629515C
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-11 04:11:55 UTC
File Type:
Binary (Archive)
Extracted files:
394
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 9dec2e1908b5f89bf52d119eba97a910bfdbd9b1e8ceda59d0a45e8aea9ee363

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments