MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b2c94002cd74ee29e196a03dc34a172cac3e669624a4fbd4e334bd3e03090df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 2 File information 4 Yara Comments

SHA256 hash: 6b2c94002cd74ee29e196a03dc34a172cac3e669624a4fbd4e334bd3e03090df
SHA3-384 hash: 602e680837a7ae7078f6f0c4b3826624ab5a6cf8a2427cdf27f6f0dee7769dbd449bd44c4b1ae02e2a08d7a66ad55ddc
SHA1 hash: bdff2549a6b8d3434fbc907bc360e612f8c0f975
MD5 hash: 315a2ba79c6d6e2eafd4c666132bbde1
humanhash: mars-stream-helium-lion
File name:PEDIDO DE LICITAÇÃO 29-6-2020_pdf.rar
Download: download sample
Signature Loki
File size:424'722 bytes
First seen:2020-06-29 18:01:40 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:EXwi9gZjs1sno/rF6jehyuSFh76I4I0IuqwsspdrEW8dKS:UzsEh6jGyzh7uFqlOrEd
TLSH 4794238B37AD586C595707B31880AD737B34998BCAB3215349B1E3DCE3A2559CBD8B10
Reporter @abuse_ch
Tags:BRA geo Loki rar

Malspam distributing Loki:

Sending IP:
From: Universidade de São Paulo <>
Subject: PEDIDO DE LICITAÇÃO (Universidade de São Paulo) EUI894/BU4600
Attachment: PEDIDO DE LICITAÇÃO 29-6-2020_pdf.rar (contains "updated file_pdf.exe")


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 30
Origin country US US
ClamAV Sanesecurity.Malware.27382.Rar5Heur.UNOFFICIAL
CERT.PL MWDB Detection:n/a
ReversingLabs :Status:Malicious
Threat name:Win32.Trojan.Injector
First seen:2020-06-29 17:01:08 UTC
AV detection:28 of 48 (58.33%)
Threat level:   5/5
Spamhaus Hash Blocklist :Malicious file
VirusTotal:Virustotal results 23.73%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



rar 6b2c94002cd74ee29e196a03dc34a172cac3e669624a4fbd4e334bd3e03090df

(this sample)

Delivery method
Distributed via e-mail attachment