MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26f99167b48a4175d40c42c05c9d38febe5cd022b527187715ebcd7814382776. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 26f99167b48a4175d40c42c05c9d38febe5cd022b527187715ebcd7814382776
SHA3-384 hash: 96f25c12d8941439eb14c30c320eac0589a35e9d73b5bc829cc654a24a09ade2c2c88aaff90126080f9a0a6a4682bb49
SHA1 hash: 538e6d9ec9e8ccb150648d12636a557c861cf23e
MD5 hash: e10e3e54a3f7392a2efaaa810f322652
humanhash: cat-high-victor-early
File name:Image001.png.gz
Download: download sample
Signature Loki
File size:619'117 bytes
First seen:2020-10-23 09:29:15 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:13woQmB7GKRPLk9JCvTKVFo9faBpcDSCstYTFawWWFWBDZGAOC/uRJWyLTj:GoQeG2DsJCrkw+buTpUBDZ3r/E
TLSH BAD423D15905E88DEE132467D9ECFC908B2FABB2C74D6C7487B91CE4826D2649D6038F
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: ns31163772.ip-51-91-220.eu
Sending IP: 51.91.220.203
From: Berda Huseyin <berda@arilarsaglik.com>
Subject: Re: 回覆: Re: AW: Transfer Copy
Attachment: Image001.png.gz (contains "Image001.exe")

Loki C2:
http://qataracfridgerepaire.com/wp-admin/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-23 08:37:08 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 26f99167b48a4175d40c42c05c9d38febe5cd022b527187715ebcd7814382776

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments