MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d698ff741dc55a69e143e3a77644eb457197cf076e6c5a0048e382eb7373e3ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d698ff741dc55a69e143e3a77644eb457197cf076e6c5a0048e382eb7373e3ec
SHA3-384 hash: 818fac1520376241967fb3130bc74462e7802a35a7989787be6a5f55aafeaf308fe24f713bf1f62aef9cccdaca2a7b69
SHA1 hash: 94a765a8abf112d57e43ddc74333de0b95d07e09
MD5 hash: 62b3a31fa2d0d325b81c259363ad6596
humanhash: cup-lion-lamp-sodium
File name:scan-711940_pdf.gz
Download: download sample
Signature Loki
File size:386'918 bytes
First seen:2020-05-18 07:11:24 UTC
Last seen:2020-05-18 11:40:12 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:XClwUgJaINdgL4x01L70ZTZXO8uRyap4aypVyey1ec4bqrkt/q96p3drkd2seXDZ:X0SHb01iVXOroyO1jty6ptgVBAR
TLSH 1384237F258C7E64F0162E81BDC7412636133D1D0EEB760D8B29BDD6A19CEF90A12A17
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 00:04:00 UTC
File Type:
Binary (Archive)
Extracted files:
295
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip d698ff741dc55a69e143e3a77644eb457197cf076e6c5a0048e382eb7373e3ec

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments