MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3e49bef9d1b612c0bc81006ad86653e39b23a731185183d9c7e5bcd3f1c364c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: b3e49bef9d1b612c0bc81006ad86653e39b23a731185183d9c7e5bcd3f1c364c
SHA3-384 hash: 1fc79858143756d5b3f5aa2a7634d939f7d69277f003f77666051b758e421c55443b06c290140d5a53ddf3b2d5eca7c0
SHA1 hash: 09387bc94f2d1c46d41d30f7baecf47586a06d8f
MD5 hash: bcf2285a235517896f5f57e3c1c05291
humanhash: uranus-orange-kitten-crazy
File name:SOA.arj
Download: download sample
Signature Loki
File size:225'357 bytes
First seen:2020-06-17 10:09:55 UTC
Last seen:2020-06-17 14:49:32 UTC
File type: arj
MIME type:application/x-rar
ssdeep 6144:h5UHraOL7ysJcTIOU7vd2RG75YhBUnWP9LgKE:h5ULb7ysJ+I1mhP9Ls
TLSH 0224235FE8B8E6A18F809B72243D685DF0A4C166EE6C3C2FC959EB1D5C32655F492330
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: klemsan.pw
Sending IP: 23.254.211.57
From: hr@klemsan.pw
Subject: RE: UPDATE SOA
Attachment: SOA.arj (contains "SOA.exe")

Loki C2:
http://remote1.gq/Bobby/fre.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

arj b3e49bef9d1b612c0bc81006ad86653e39b23a731185183d9c7e5bcd3f1c364c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments