MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0fea9f4e316e864af78c608133f3acba4d76675cccadb8231864b8f3328c16d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 0fea9f4e316e864af78c608133f3acba4d76675cccadb8231864b8f3328c16d7 |
|---|---|
| SHA3-384 hash: | 5df238301f0c81cb607920848f8edc6b97e5176a5ce3999e0681d128dc0811ed4e2451a37254b8838acac724278f562f |
| SHA1 hash: | 86e21a837938cd23fee54be39fb8092d89c70ca7 |
| MD5 hash: | 1a230e2476b96f8b0c56cc636e7ab664 |
| humanhash: | oregon-four-wyoming-fix |
| File name: | STS CARGO SHIPMENT.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 178'432 bytes |
| First seen: | 2021-01-08 19:05:35 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 3072:WWwR1YsagKQ88U3YOnMBqe9lmaYOTtFM6/sLP/FtCHGWOxbdIHFEj9D0D:HwfYRaOnM0ezcV4jOIlS9Do |
| TLSH | E80423805F4FA2DEC20CD6406FEEC0641CF97BC5644F6A22BEF390CD35956E411A6EA6 |
| Reporter | |
| Tags: | gz Loki |
abuse_ch
Malspam distributing Loki:HELO: hrl.comsats.net.pk
Sending IP: 203.124.39.163
From: MAILER COSYS AMERICA <atiqa@rdlpk.com>
Subject: STS CARGO SHIPMENT ARRIVAL NOTICE
Attachment: STS CARGO SHIPMENT.gz (contains "STS CARGO SHIPMENT.exe")
Loki C2:
http://impulsetechnosoft.com/xx/Panel/fre.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
337
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-01-08 19:06:08 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.