MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f
SHA3-384 hash: 86f1bcee26cd064f6c35e83fa14ceaa8e26534d60884bd4299736d36d7c822eb8e06969fcd40fe115ea6bc4bd8232240
SHA1 hash: c487d9337e50d2ecfbfb1eb7771df38a54fd1164
MD5 hash: 4a2565717bc8326de771a970593c1194
humanhash: green-charlie-football-kitten
File name:RFQ scope of requirements..gz
Download: download sample
Signature Loki
File size:348'855 bytes
First seen:2020-06-30 12:43:51 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:wTXgvwQF7FZOONDDN7gOe93rl02/tSFPYMO1/WPl8Mp6r6JnEH5sRQgYWfaW3UeI:wTQ4OEsDB7bA3REJNRtF6r6JnSQ3UMh0
TLSH FF742312E65D9C93E31012D8C91E7CFE796FAED4ABCA558CB50518FFB46C9B36023209
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: navmailsrv.navayuga.com
Sending IP: 207.244.65.197
From: Bader J. Al-Hajeri <info@traxconsulting.com>
Reply-To: Trax@consultant.com
Subject: Request For Commercial Offer.
Attachment: RFQ scope of requirements..gz (contains "gunzipped")

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-06-30 12:45:06 UTC
AV detection:
36 of 48 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 7da7d8db8c81b1335b1da547c242e6e7408319c517c4c146d31dd57400487b2f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments