MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2ce0a29c042cef702bb8faef1efafbfd2a0976f71b112a868dec8da9acbf793. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a2ce0a29c042cef702bb8faef1efafbfd2a0976f71b112a868dec8da9acbf793
SHA3-384 hash: 148e62b03e4883bade04d24afe71cb2dbb7e276e33afbbeb14425920bd077e3714edf6fb1c545802014b56f432db1183
SHA1 hash: 712fc3b317cbb4873f9887d7587842b3d6452497
MD5 hash: 7742ef17f5d24acbea2c91a1c99148f8
humanhash: white-music-virginia-monkey
File name:INVOICE.zip
Download: download sample
Signature Loki
File size:250'152 bytes
First seen:2020-06-04 06:39:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:sYrDhRpRIWtZFwNsJwR1fGl77xh2Q/XzY6MVvuaZhDuTpeNsEO8aijgeXgGXrowN:suRSiZ6r4N3EiaPCTquz0roNsyneZdX
TLSH 05342306A135EAC7966F843DFF2041AAFA79159BCE9D12A44D0437B291301C3FB49AED
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail0.473.celumltd.casa
Sending IP: 165.22.94.14
From: NCS LINE WORLD WIDE - HQ <info@ncsline.com>
Subject: INVOICE
Attachment: INVOICE.zip (contains "Darren-REFUD-PM.exe")

Loki C2:
http://netease-163mail-com.tk/Darren/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-04 07:22:12 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip a2ce0a29c042cef702bb8faef1efafbfd2a0976f71b112a868dec8da9acbf793

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments