MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 146578c2d7044d069706b80ec8807cfadadfd7fde632f2c6657aafc65c60e59e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 146578c2d7044d069706b80ec8807cfadadfd7fde632f2c6657aafc65c60e59e |
|---|---|
| SHA3-384 hash: | c233051d764ef785aee1b1f7e8db5e352107b28e55cf483df305e46b8760f22e6564c6c1ffa4306593783f7b3fa3c3d7 |
| SHA1 hash: | e4b189f985df61c76c4f5820a36f915a229fb27d |
| MD5 hash: | b11c664e735dbd8a3c12642501ca81b1 |
| humanhash: | georgia-utah-south-delaware |
| File name: | Packing list, invoice and bill of lading_pdf.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 356'991 bytes |
| First seen: | 2020-10-20 14:58:19 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:z8idc4IPm8KkWpQHSbBXwZ0I+NMlo9FuJJ5q4APZYlx7aLjuON0lj7X9oCaFWyC1:z1ezUuSyOjN9uJJ5qdBYH7cjuHr9oCi2 |
| TLSH | 85742362F1FED9FE6E5212A84A130720188CF414D655898D4FEBA89F3F5066DFF94823 |
| Reporter | |
| Tags: | DHL gz Loki |
abuse_ch
Malspam distributing Loki:HELO: mx.itsource.com.ua
Sending IP: 91.197.146.118
From: DHL Global Mail Inc © <bdcare@dhl.com>
Reply-To: Customer service <ricknicolas.aol@hotmail.com>
Subject: DHL E-Shipping Notification Notice- AWB 7248297469
Attachment: Packing list, invoice and bill of lading_pdf.gz (contains "Packing list, invoice and bill of lading_pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-20 12:49:13 UTC
AV detection:
14 of 48 (29.17%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.