🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcda66531993c18d2da2b69dd5de60f5b8306c2d78dd87c0aa036e51d404f36f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dcda66531993c18d2da2b69dd5de60f5b8306c2d78dd87c0aa036e51d404f36f
SHA3-384 hash: 5d053b8ca25cc44f37157d0975fb0694507750f4c0f84b76254d5a87f1244c5e5028b710857cfb0e1b618521fb940c96
SHA1 hash: 4d569461f2d6dd937c098f528d500b2905fbea2a
MD5 hash: 00a492d883ed46f9734741b44ff28c33
humanhash: william-edward-comet-ten
File name:Payment-Ref009980-RM2-0009880-pdf.arj
Download: download sample
Signature Loki
File size:427'852 bytes
First seen:2020-04-29 07:06:15 UTC
Last seen:2020-04-29 21:32:54 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:yo1alcHUl5NS7GqKBX1m83VohszQwz9qYgJ/V1g//StTrIObIljIribNHgtqadnZ:FHc5QXKBX1m8FxlcYW7tT7YIeWqgZ
TLSH 0E9423079B1973D89B1B0A1AE90A60B75791F546FE0C38FEF85253D30C8748A1E9B94F
Reporter jarumlus
Tags:Loki Lokibot

Intelligence


File Origin
# of uploads :
3
# of downloads :
1'429
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-29 05:25:36 UTC
File Type:
Binary (Archive)
Extracted files:
41
AV detection:
24 of 30 (80.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments