MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cacd6006ce6802be9d56a75a8ccdfb9ae011e7f1ba54514cb096f64497656d2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: cacd6006ce6802be9d56a75a8ccdfb9ae011e7f1ba54514cb096f64497656d2d
SHA3-384 hash: 6397ffa560057c5f9ade9db0f8306cb070440d9f1dbcfe0595078c69e862976dbc43f8ed3c49ba77fe07bcd4b7971d18
SHA1 hash: 926cf9bb5082bc390b529f639fde3b32e6fd4f03
MD5 hash: d95ecad8ea717c6696926e430cea32f6
humanhash: lithium-black-berlin-chicken
File name:copy-PO177170_pdf.gz
Download: download sample
Signature Loki
File size:363'955 bytes
First seen:2020-05-28 05:14:28 UTC
Last seen:2020-05-28 05:42:34 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:/X+SO2lJyWTod7XWUaesl3q/NKs5PGUGXNWpmLcvFnHlaSkAUukkE0e+NfLPOu:/OSOAyWkdzWTe63qgqPGUGIpqcvnffu2
TLSH 2C7423D457418CA1B31FD252A993F3476F2CA41EF987BEAA88231EC842C9B55C373C15
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-28 04:37:28 UTC
File Type:
Binary (Archive)
Extracted files:
296
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip cacd6006ce6802be9d56a75a8ccdfb9ae011e7f1ba54514cb096f64497656d2d

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments