🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e168dbc0fa7303711159ce55109a1aeaa6c2b28f45b97989d2c1bd8d7b96332. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 9e168dbc0fa7303711159ce55109a1aeaa6c2b28f45b97989d2c1bd8d7b96332
SHA3-384 hash: d82d6c553d3c4492d4f675dceaf592b2f8c399f9e3bd11c344b54460e3e6c9cbb49797193e321162497a6ac148c14920
SHA1 hash: f5dd67b20811459c35e7e559a9f6ad8fb381bec8
MD5 hash: 03693372fc2fd546adacb831c5c534a8
humanhash: black-colorado-ink-fourteen
File name:DOCUMENT 7782231.xlsx
Download: download sample
Signature Loki
File size:194'216 bytes
First seen:2022-03-30 08:31:53 UTC
Last seen:2022-03-31 17:36:55 UTC
File type:Excel file xlsx
MIME type:application/encrypted
ssdeep 3072:7S5VzrnjAmF8eA2EabfGV5ewvHSd2/wSMz8TJ4cTh2nNEc5LOv4TVhfbDA:gSeA2Lb+VV1/LMzs4l1Ov4hVXA
TLSH T1F9141200B3C09427C7490FB2C9D36DA19A5BFD11664D8CE6692AF0AC53B94DDBE18F8D
Reporter proxylife
Tags:CVE-2017-11882 Loki Lokibot xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE dump
Detection: VelvetSweatshop

MalwareBazaar was able to identify 6 sections in this file using oledump:

Section IDSection sizeSection name
164 bytesDataSpaces/DataSpaceInfo/StrongEncryptionDataSpace
2112 bytesDataSpaces/DataSpaceMap
3208 bytesDataSpaces/TransformInfo/StrongEncryptionTransform/Primary
476 bytesDataSpaces/Version
5187560 bytesEncryptedPackage
6224 bytesEncryptionInfo

Intelligence


File Origin
# of uploads :
2
# of downloads :
412
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Details1363113424060021.xlsx
Verdict:
Malicious activity
Analysis date:
2022-03-31 06:07:51 UTC
Tags:
encrypted opendir exploit CVE-2017-11882 loader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Searching for synchronization primitives
Launching a process
Creating a file
Сreating synchronization primitives
Sending an HTTP GET request to an infection source by exploiting the app vulnerability
Creating a process from a recently created file
Result
Verdict:
Malicious
File Type:
OOXML Excel File with Embedding Objects in Encrypted Excel File
Document image
Document image
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
control.exe CVE-2018-0802 embedequation exploit packed replace.exe shellcode VelvetSweatshop
Label:
Malicious
Suspicious Score:
9.9/10
Score Malicious:
99%
Score Benign:
0%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
expl.evad
Score:
96 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Document-OLE.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2022-03-30 08:32:07 UTC
File Type:
Document
Extracted files:
53
AV detection:
14 of 42 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Checks processor information in registry
Enumerates system info in registry
Launches Equation Editor
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Loads dropped DLL
Uses the VBS compiler for execution
Blocklisted process makes network request
Downloads MZ/PE file
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments