MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 bd7f552c297a1385e3ef57aae30d79d91efa32d574e6ecfd58131a08ecf8d82a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | bd7f552c297a1385e3ef57aae30d79d91efa32d574e6ecfd58131a08ecf8d82a |
|---|---|
| SHA3-384 hash: | c4bd6fc80df7d12ce1cdaf01fe750d9798d8e86e5a998ffb0b98f521e9d1bf6ee9c3ee86693e28797af4ab86c134d0f8 |
| SHA1 hash: | f9ef17069a43343bc1e96f714cc17b05920c4fd8 |
| MD5 hash: | b7cddb0fb84782464e2c41c62e952628 |
| humanhash: | low-salami-magnesium-salami |
| File name: | SDT_R224e18032356210_XLS.arj |
| Download: | download sample |
| Signature | Loki |
| File size: | 185'778 bytes |
| First seen: | 2020-10-05 11:56:28 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 3072:DUrPgyE8GFUHM43OHxzbHTUKBeWkPi7BNt+svLYNvnDD1CtjoUd89Q/Ko1l28rAi:DecUstHxnYspkPiztbvLM/DDgRDd8+d1 |
| TLSH | B3042266A8D52864CC8B30284432AA24EFBF67D3236B5A7F125497DFE81ECD04527D63 |
| Reporter | |
| Tags: | arj Loki |
abuse_ch
Malspam distributing Loki:HELO: res14-141.cp.htz.privatedns.biz
Sending IP: 88.99.56.141
From: berenguelpaulbryan@gmail.com
Subject: RE: Approved Proforma _ Grassco
Attachment: SDT_R224e18032356210_XLS.arj (contains "SDT_R224e18032356210_XLS.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-05 06:14:38 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.