MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cbd212886a6601d70a5823d971b229dbf4d2bf97985b2863e610ab3730e533b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cbd212886a6601d70a5823d971b229dbf4d2bf97985b2863e610ab3730e533b3
SHA3-384 hash: e70c85098ced2f90843070ab3ca8a3b6b9d16d1bc9ebe956486369cff16792d957d626a907b5f750bb04c7db20e51d1d
SHA1 hash: 7bcc59de1d7027049e6a78409f176ead4cf2d0d9
MD5 hash: 56a10603069a19c315d6724ceaa5c54f
humanhash: happy-network-massachusetts-enemy
File name:Request For Price quotation 15-01-2020.pdf.rar
Download: download sample
Signature Loki
File size:140'966 bytes
First seen:2021-01-15 07:16:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:74UwYQyCc2afvtUTWrMIakP13jRLokUL8TtB+ZgBvzw17r3sWFtboWECx:74jYYafFU6U+1xoVwTtBCgl27r3sOtbl
TLSH 33D31207DEBE88868DC7009DB2DD4925FD7EA8DE0D77F89A2460409817CD89F544EACE
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: smtp.outgoing.loopia.se
Sending IP: 93.188.3.38
From: NATIONAL UNIVERSITY OF SINGAPORE <paunovic@mehanika.rs>
Subject: Request For Price quotation (NATIONAL UNIVERSITY OF SINGAPORE) NUS894/BU463
Attachment: Request For Price quotation 15-01-2020.pdf.rar (contains "newcrypted_pdf (1).exe")

Loki C2:
http://51.195.53.221/p.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
147
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2021-01-15 07:17:33 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar cbd212886a6601d70a5823d971b229dbf4d2bf97985b2863e610ab3730e533b3

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments