MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee32f4fd8924c24ce06a7a6bcd9f99d257b6fe7d20645d35ec93fa84d1b3fc1c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ee32f4fd8924c24ce06a7a6bcd9f99d257b6fe7d20645d35ec93fa84d1b3fc1c
SHA3-384 hash: 326a63ab64e3f714cc1327404f84914827bc7a5ed7d57a649f58402e2af0a68de96460635e8c3080929b69725bc1e53d
SHA1 hash: ee27b4f89ff45519eb30b8b2dfa653beaed91cc8
MD5 hash: 7ebbf49fb0f2fb6ecd0469e69acef435
humanhash: winner-mango-foxtrot-march
File name:PO.rar
Download: download sample
Signature Loki
File size:25'047 bytes
First seen:2020-05-11 09:27:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:RiKAPQbWIUnTa3xYRrmemTU1a2EGKtoVBMeKtHa:cKgQi/nTa3SeQZXPfvKtHa
TLSH 4CB2E1CB8A5883F574B1185ACDF503DAFFAD5E7129619860BD4AF0222EFCCC629C95D0
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: d166.x-mailer.de
Sending IP: 212.162.13.166
From: Catherine Minio<c.mini@blancmariclo.com>
Reply-To: <c.mini@blancmariclo.com>
Subject: Quotation for new order
Attachment: PO.rar (contains "PO_pdf.exe")

Loki C2:
http://egamcorps.ga/~zadmin/lmark/gld/mode.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Androm
Status:
Malicious
First seen:
2020-05-11 09:36:45 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar ee32f4fd8924c24ce06a7a6bcd9f99d257b6fe7d20645d35ec93fa84d1b3fc1c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments