MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2836d55ca2f37f00c3bb9b17c371be7da15c597e0f008d85727eb3c0c7b777f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f2836d55ca2f37f00c3bb9b17c371be7da15c597e0f008d85727eb3c0c7b777f
SHA3-384 hash: f3ce74de815080bbb4c9b7d5127eb26ea8414d4d5bb5a2684de7efc5318d4829b9b0457b59c88b865f8d79754ce3559b
SHA1 hash: 2a244ad10995459ffc18533447dc471ee1cac6b3
MD5 hash: 185f53e4f92132fddc68314a2269a7b7
humanhash: johnny-mexico-high-table
File name:Ref 0180066734.img
Download: download sample
Signature Loki
File size:1'376'256 bytes
First seen:2020-10-13 05:53:11 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:+rZD1N4x2IdqcvLyNGs6eWsw2f4qhfh9/Am4EeFDtF6mruJcGQkBzQey:+9D1OwWq2ycLeWPbqhfHH4EeFDf+m
TLSH B055C0E1F395ED85E26E4F39843298108BF2FF6A5936C34F2C9C309816B77926156B07
Reporter abuse_ch
Tags:img Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: smarthost1.gohsphere.com
Sending IP: 173.0.142.242
From: PAGOS <colosio_her@camposreyeros.com>
Subject: Re: DEVOLUCIÓN DE PAGO TT (Ref 0180066743)--
Attachment: Ref 0180066734.img (contains "Ref 0180066734.PDF.bat")

Loki C2:
http://195.69.140.147/.op/cr.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Agensla
Status:
Malicious
First seen:
2020-10-12 20:14:37 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

img f2836d55ca2f37f00c3bb9b17c371be7da15c597e0f008d85727eb3c0c7b777f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments