MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d48801d9c2e0df136f6e5c4c31b317b6d7d5f95c2201bf60b7480c62973d11f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d48801d9c2e0df136f6e5c4c31b317b6d7d5f95c2201bf60b7480c62973d11f2
SHA3-384 hash: 15d2b10c21fa3d0eeb012098c1f47a3a4e79e47fa9cec2b02ff5b21bf7294c7b64498f3b182bd665918952dd16c80620
SHA1 hash: b47611061c660d97047e21528255a8cd57bcc1ee
MD5 hash: 048832c9fcf5146ceb1c100858149f9d
humanhash: jig-delta-hawaii-table
File name:PO20201016.cab
Download: download sample
Signature Loki
File size:375'890 bytes
First seen:2020-10-16 12:21:02 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:OJvn22F8aJwFC9k27NUdW8/gIn4HmMPrcmufsHZAlOtlu8VFS5j0d:OJvnX8tC9k27NUQqbgjduYZ0eFSqd
TLSH EB84237ECA621CB1450E1FB3CBB94E5819A5A338339D85062DA58BFA1EED81CDD8D214
Reporter abuse_ch
Tags:cab geo KOR Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail-smail-vm49.hanmail.net
Sending IP: 203.133.180.237
From: HYUNDAI PF INDUSTRY Co.,LTD <jsa7945@hanmail.net>
Subject: 견적 요청의 건
Attachment: PO20201016.cab (contains "NL1re6zRZryng51.exe")

Loki C2:
http://heliopoliss.com/goodluck/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Spyware.Stelega
Status:
Malicious
First seen:
2020-10-16 02:53:22 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

cab d48801d9c2e0df136f6e5c4c31b317b6d7d5f95c2201bf60b7480c62973d11f2

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments