MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ed9f49411d20c3be8f39110128f4ec4115ab235c2d090f67e9d090831b68129c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ed9f49411d20c3be8f39110128f4ec4115ab235c2d090f67e9d090831b68129c
SHA3-384 hash: ab2afef92bc641846c972d6b79d5e42eccbf0b064458a68866ec80061ecaf08cb611fb04220632822877bec60148bd47
SHA1 hash: b5ecbbdf11cb24c50f45eb4368ab65cfba2858ef
MD5 hash: 0b9c7875f7e5bd475861a6d9ac75389e
humanhash: edward-sweet-mississippi-sweet
File name:VENDOR DETAILS_pdf.gz
Download: download sample
Signature Loki
File size:262'348 bytes
First seen:2020-10-28 07:41:47 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:f0rY4+j1tInlz2QFq6npsEcfI+Vr9IOM0LmA7ekDX5svm:fZ4nlz2QAbxfI+raAmA79DX5su
TLSH 0D4423B08126CD5F6DCECB0DB1691D43EB955DF6C9B63819B86718DD2C38A3913A0C8B
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.cre3d.com
Sending IP: 209.140.30.170
From: PT. Intervet <info@merck.com>
Reply-To: info@merck.com
Subject: Re: NEW PO#20817
Attachment: VENDOR DETAILS_pdf.gz (contains "VENDOR DETAILS_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Racealer
Status:
Malicious
First seen:
2020-10-28 06:12:08 UTC
AV detection:
9 of 29 (31.03%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz ed9f49411d20c3be8f39110128f4ec4115ab235c2d090f67e9d090831b68129c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments