MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 cbd212886a6601d70a5823d971b229dbf4d2bf97985b2863e610ab3730e533b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 3
| SHA256 hash: | cbd212886a6601d70a5823d971b229dbf4d2bf97985b2863e610ab3730e533b3 |
|---|---|
| SHA3-384 hash: | e70c85098ced2f90843070ab3ca8a3b6b9d16d1bc9ebe956486369cff16792d957d626a907b5f750bb04c7db20e51d1d |
| SHA1 hash: | 7bcc59de1d7027049e6a78409f176ead4cf2d0d9 |
| MD5 hash: | 56a10603069a19c315d6724ceaa5c54f |
| humanhash: | happy-network-massachusetts-enemy |
| File name: | Request For Price quotation 15-01-2020.pdf.rar |
| Download: | download sample |
| Signature | Loki |
| File size: | 140'966 bytes |
| First seen: | 2021-01-15 07:16:42 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 3072:74UwYQyCc2afvtUTWrMIakP13jRLokUL8TtB+ZgBvzw17r3sWFtboWECx:74jYYafFU6U+1xoVwTtBCgl27r3sOtbl |
| TLSH | 33D31207DEBE88868DC7009DB2DD4925FD7EA8DE0D77F89A2460409817CD89F544EACE |
| Reporter | |
| Tags: | Loki rar |
abuse_ch
Malspam distributing Loki:HELO: smtp.outgoing.loopia.se
Sending IP: 93.188.3.38
From: NATIONAL UNIVERSITY OF SINGAPORE <paunovic@mehanika.rs>
Subject: Request For Price quotation (NATIONAL UNIVERSITY OF SINGAPORE) NUS894/BU463
Attachment: Request For Price quotation 15-01-2020.pdf.rar (contains "newcrypted_pdf (1).exe")
Loki C2:
http://51.195.53.221/p.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
147
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2021-01-15 07:17:33 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.