MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d675eb848a24c6b5cb7f50ec768b9b821c42a517698a8b4b42462b57014c3e34. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d675eb848a24c6b5cb7f50ec768b9b821c42a517698a8b4b42462b57014c3e34
SHA3-384 hash: d30ecb84d5d2c972aab605add4a8d4814e576d4fc9a4e7ef70b706b2935f08500015f0ca7d8115adb450d3bf8ac04110
SHA1 hash: ac5f78cfd7e77b7faed0b602079e824bd012082c
MD5 hash: f4b5296c8ff4b73c528b26ac8055a6c1
humanhash: bakerloo-vermont-south-enemy
File name:scan-023429_pdf.gz
Download: download sample
Signature Loki
File size:361'809 bytes
First seen:2020-06-08 06:09:04 UTC
Last seen:2020-06-08 08:46:53 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:30Dq+clvFa6qIJt2KAcY7swA5wwYNoR2oqzGh+rBUqdgq+ikSmya:30O+csogkYEwloMzMyBUqd4Smya
TLSH 7774236A9280632898DF514DA4CBD7627A2F93D03D4BA46532F6DFF44AAC35C1242DCF
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
2
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-06-08 05:29:53 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip d675eb848a24c6b5cb7f50ec768b9b821c42a517698a8b4b42462b57014c3e34

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments