MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d86dab59f4a3384c39a64827f5878e7c8e98ad060ab85c8c5a6c7b953d54489a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d86dab59f4a3384c39a64827f5878e7c8e98ad060ab85c8c5a6c7b953d54489a
SHA3-384 hash: 8bc488796e0aba64ca2125f4f84301d69d76aaa9f141f8c8df1bca665869912db01b2667f43297cc85a8ae6247592d2c
SHA1 hash: 92326da61ba486166cf5a1c1f655f2f2b7156e2b
MD5 hash: deaa8aed3b5164c5938d950a7d68f81a
humanhash: indigo-kentucky-three-india
File name:PURCHASE ORDER FOR COVID-19 SHIPMENT_pdf.arj
Download: download sample
Signature Loki
File size:777'406 bytes
First seen:2020-05-14 07:24:40 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:82kXVntgwMXcNsf0sykMuSmp3womOnP2mT40Vb5f6QlmCYQU4j8GW5HDVy38jTKP:82nvykMudm+20b5fplVj89jVyMmRvE4z
TLSH D9F433E7EF7317740B182E3D69C698A6D856EB30A277C9018D78CD8E97FC906A101787
Reporter abuse_ch
Tags:arj COVID-19 Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: s1.smallhost.in
Sending IP: 103.46.239.70
From: Wilhelmsen Sunnytrans Co. <thang_hang@wilhelmsen.com>
Subject: Due to COVID'19 - NEW PURCHASE ORDER
Attachment: PURCHASE ORDER FOR COVID-19 SHIPMENT_pdf.arj (contains "PURCHASE ORDER FOR COVID-19 SHIPMENT_pdf.exe")

Loki C2:
http://attlogistics-vn.com/first/chief2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-14 07:17:35 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip d86dab59f4a3384c39a64827f5878e7c8e98ad060ab85c8c5a6c7b953d54489a

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments