MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ebd56ad465ec62b381be139ee332d7bfdc0179b83fd6dd80cfab46d192707fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0ebd56ad465ec62b381be139ee332d7bfdc0179b83fd6dd80cfab46d192707fa
SHA3-384 hash: 97856ffc5b963bc1bca9dbd3de0534c0f801cac8095f37c00c9ed301a493d2bfddb1141b54a5ef2aeac7c9706cabdc4d
SHA1 hash: f5ed0b0c568018fb15033363e5f57dfe3aa65089
MD5 hash: 344aaffbeba05d6d174e90482570440b
humanhash: rugby-kentucky-lion-vermont
File name:DHL Consignment Details.gz
Download: download sample
Signature Loki
File size:230'137 bytes
First seen:2020-10-26 15:14:00 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:tRwGUZZeZRL3QnxoVUMT5/g4FZLg+/c3xNKcmTwv:tLUZZeLLAnayMhvzchNK5wv
TLSH 732423A160C4850E4C78A2A475AAFB9E434D9B3ECDA9B1F18F151DFF858EC127472E70
Reporter abuse_ch
Tags:DHL gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: larisaevents.gr
Sending IP: 213.239.215.207
From: DHL Express <customercare@dhl.com>
Subject: DHL CONSIGNMENT NOTIFICATION
Attachment: DHL Consignment Details.gz (contains "gunzipped")

Loki C2:
http://195.69.140.147/.op/cr.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Shelma
Status:
Malicious
First seen:
2020-10-26 12:42:47 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 0ebd56ad465ec62b381be139ee332d7bfdc0179b83fd6dd80cfab46d192707fa

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments