MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b443d6cb45b16b895c9b3cf48d68cc90a43fd22468796e01028d4e7fb47598e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1b443d6cb45b16b895c9b3cf48d68cc90a43fd22468796e01028d4e7fb47598e
SHA3-384 hash: e5ce2badf20ac4ddd0bbdd529020c51c69a9d08f9ec37fb3cc65f100765e819e4bae713269d362c4f5390d576077daea
SHA1 hash: fff6a66ac9dda576b52ed80aedda57f47f2e3b6d
MD5 hash: 46882e77b947f590beb305fbac4371ee
humanhash: freddie-xray-carolina-hydrogen
File name:Document_pdf.zip
Download: download sample
Signature Loki
File size:348'275 bytes
First seen:2020-06-05 13:49:30 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ESUikSC54ARVln8uIXu7UbNpOQJ/vRJM5KfGCXnk2XyrpOTaUkZyIh:ESUiFRg58G7qNg4vbuqLXxiF8aryIh
TLSH F074230CCB5331644F6C8C360E9B7A87F2D5B8D0641FA7BA5F226712E8D5CC11662A67
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-06-05 10:45:22 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 1b443d6cb45b16b895c9b3cf48d68cc90a43fd22468796e01028d4e7fb47598e

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments