MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 22e6b27cc95cc8980509b4c541c4ea029c61202ef39c7b9437603811de3acd7e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 22e6b27cc95cc8980509b4c541c4ea029c61202ef39c7b9437603811de3acd7e
SHA3-384 hash: 94e7d7bccde9ad9c6a4f0fc4701fa75141da13f85027f7c101bee0a74284ff2560d2e2e2d567559db7ac88aadd93f1e1
SHA1 hash: 31612f9eab3e5ae46f486b3b7a5a080bb9c3619e
MD5 hash: 916f77948846f3c8a7eeb8a67741cb00
humanhash: south-bacon-kitten-cold
File name:scan-4109384_pdf.gz
Download: download sample
Signature Loki
File size:348'602 bytes
First seen:2020-06-05 05:25:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:nDEntz4sX0MGvzsT+DenNKfruaErppuBmYehj2GFsTFEyYRTO8c+EKE3OGjmt+/7:nDCOsX0ngTol3EFwBmZ2GryYR5c+EKER
TLSH F37423EE404B3598960ADD8B779C64CA98DE95D708DD0577C0BCC8FE826883A577CF09
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-06-05 02:31:59 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 22e6b27cc95cc8980509b4c541c4ea029c61202ef39c7b9437603811de3acd7e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments