MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd7f552c297a1385e3ef57aae30d79d91efa32d574e6ecfd58131a08ecf8d82a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bd7f552c297a1385e3ef57aae30d79d91efa32d574e6ecfd58131a08ecf8d82a
SHA3-384 hash: c4bd6fc80df7d12ce1cdaf01fe750d9798d8e86e5a998ffb0b98f521e9d1bf6ee9c3ee86693e28797af4ab86c134d0f8
SHA1 hash: f9ef17069a43343bc1e96f714cc17b05920c4fd8
MD5 hash: b7cddb0fb84782464e2c41c62e952628
humanhash: low-salami-magnesium-salami
File name:SDT_R224e18032356210_XLS.arj
Download: download sample
Signature Loki
File size:185'778 bytes
First seen:2020-10-05 11:56:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:DUrPgyE8GFUHM43OHxzbHTUKBeWkPi7BNt+svLYNvnDD1CtjoUd89Q/Ko1l28rAi:DecUstHxnYspkPiztbvLM/DDgRDd8+d1
TLSH B3042266A8D52864CC8B30284432AA24EFBF67D3236B5A7F125497DFE81ECD04527D63
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: res14-141.cp.htz.privatedns.biz
Sending IP: 88.99.56.141
From: berenguelpaulbryan@gmail.com
Subject: RE: Approved Proforma _ Grassco
Attachment: SDT_R224e18032356210_XLS.arj (contains "SDT_R224e18032356210_XLS.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2020-10-05 06:14:38 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip bd7f552c297a1385e3ef57aae30d79d91efa32d574e6ecfd58131a08ecf8d82a

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments