🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d96a79c4c6781f4715c2a8f99c4255b41bff21aa9aa46cb0f9cf334635a32513. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d96a79c4c6781f4715c2a8f99c4255b41bff21aa9aa46cb0f9cf334635a32513
SHA3-384 hash: cd440046c6d66f304d2c6e79d0330c2767d5207ed57ae089d8b1d65e7df31587707ea3ca410666806f5a694ceca720e8
SHA1 hash: 0648a9a6988d5b6a3c6b2c454ed658cdfcb44d46
MD5 hash: 68cddcec15d07c7fb9ad8036afcbfd28
humanhash: uranus-river-mississippi-twenty
File name:Payment Advice-090003000009300000000-pdf.arj
Download: download sample
Signature Loki
File size:384'720 bytes
First seen:2020-04-23 09:29:23 UTC
Last seen:2020-04-23 16:26:25 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:AU08ziVjWegzt4EjgUlvPdaV3BmU/5vlfdyVYSPResEZoyX8dVTdazViEsy3o7:ASziVjWbTlvP+3YU/5vlfoVYSpezqyXs
TLSH DA84234C3EC51B1F8B87E0C76E58A3AEF8A977C9D5AE2867831EC3915A509F24134374
Reporter jarumlus
Tags:Loki Lokibot

Intelligence


File Origin
# of uploads :
2
# of downloads :
1'409
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-23 18:57:20 UTC
File Type:
Binary (Archive)
Extracted files:
60
AV detection:
25 of 31 (80.65%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments