MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd40a06fa2245839ccd4cb5868a8c05f2336515cd701e7d6b480080517e2a43c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bd40a06fa2245839ccd4cb5868a8c05f2336515cd701e7d6b480080517e2a43c
SHA3-384 hash: 721aee27da50168a54e8637fcfa7bd4db78293e89577c6eff23095c23bf735dcf74c29bea6011eb3c09ff07687815239
SHA1 hash: c4b07da240c2d1d9c38b7f630a93b8b27b711cec
MD5 hash: e9d4b7078b125274b2a9ccb862bf9246
humanhash: stream-steak-zulu-glucose
File name:Pdf Payment Invoice.zip.rar
Download: download sample
Signature Loki
File size:292'652 bytes
First seen:2020-10-26 05:32:53 UTC
Last seen:2020-10-28 01:19:59 UTC
File type: rar
MIME type:application/x-rar
ssdeep 6144:msY1joTHoh0rOhMkOnXM2ONwZsDeX4Ol47YfSboCThsP:RsjoTIh0rO4MnvOycxP
TLSH 7D5423E231264B60877F9D1B33929EC1B1FBA3B8C45246C7DC67957B1E00916C3545BB
Reporter GovCERT_CH
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-26 04:03:35 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar bd40a06fa2245839ccd4cb5868a8c05f2336515cd701e7d6b480080517e2a43c

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments