MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loda


Vendor detections: 14


Intelligence 14 IOCs YARA 10 File information Comments

SHA256 hash: 2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba
SHA3-384 hash: f9dbd29739060a03ea40d63f9c7f971d67ac373d6cd40bf5ef5294ca0680fea2e5bf838b07b06a2e7e17b919d10be9a1
SHA1 hash: 8b78edc4466399b0a4158f018f614dcf01f255c4
MD5 hash: 61e7b67b3ca5412726f99a469d54c545
humanhash: earth-mirror-seventeen-pizza
File name:msedge.exe
Download: download sample
Signature Loda
File size:1'122'816 bytes
First seen:2026-08-04 23:21:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ef471c0edf1877cd5a881a6a8bf647b9 (83 x Formbook, 34 x Loda, 33 x Loki)
ssdeep 24576:3hloDX0XOf4btEJNO5HjXp/LI6oVjbBqsTg92lz:3hloJfsEvUHLpDoBqsTi2l
TLSH T19435132A4E8BBCDFE41459B45496DBD6066CDFA5B4E506EC30E4EF3DA3A24748600FB0
TrID 32.8% (.EXE) UPX compressed Win32 Executable (27066/9/6)
32.2% (.EXE) Win32 EXE Yoda's Crypter (26569/9/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.9% (.EXE) Win64 Executable (generic) (6522/11/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Magika pebin
dhash icon f0d4820ccecef4f8 (12 x AsyncRAT, 10 x XWorm, 8 x CoinMiner)
Reporter TannerFilip
Tags:exe Loda LodaRAT RAT UPX
File size (compressed) :1'122'816 bytes
File size (de-compressed) :1'608'704 bytes
Format:win32/pe
Unpacked file: 757060d1a348f54c2fceeb3337e0e8b8a984d3f3001ffc27771dd49f559254e7

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
US US
Vendor Threat Intelligence
Malware configuration found for:
AutoIt PEPacker
Details
Malware family:
ID:
1
File name:
https://florida.courtadr.com/search.php?ADR_ID=7:26-cv-45259-ADR
Verdict:
Malicious activity
Analysis date:
2026-08-04 20:26:34 UTC
Tags:
loader loda rat autoit xworm remote upx evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% directory
Deleting a recently created file
Searching for synchronization primitives
Launching a process
Searching for the window
Creating a file in the %AppData% subdirectories
Using the Windows Management Instrumentation requests
Running batch commands
Creating a process with a hidden window
Creating a process from a recently created file
DNS request
Connection attempt
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
autoit compiled-script evasive lolbin microsoft_visual_cc obfuscated overlay packed packed packer schtasks upx
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-04T10:57:00Z UTC
Last seen:
2026-08-05T20:59:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
5 match(es)
Tags:
AutoIt Decompiled Executable PE (Portable Executable) PE File Layout Suspect Win 32 Exe x86
Threat name:
Win32.Trojan.LodaRAT
Status:
Malicious
First seen:
2026-08-04 21:21:20 UTC
File Type:
PE (Exe)
Extracted files:
34
AV detection:
21 of 36 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery evasion execution persistence privilege_escalation trojan upx
Behaviour
Modifies registry class
NTFS ADS
Runs .reg file with regedit
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
AutoIT Executable
Executes a VBScript file via the Windows Script Host.
UPX packed file
Checks computer location settings
Creates a file in the Startup directory
Executes dropped EXE
Modifies Windows Defender DisableAntiSpyware settings
Modifies Windows Defender Real-time Protection settings
Unpacked files
SH256 hash:
2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba
MD5 hash:
61e7b67b3ca5412726f99a469d54c545
SHA1 hash:
8b78edc4466399b0a4158f018f614dcf01f255c4
SH256 hash:
63c75853faa91426252a53256e36f776b7ca635bc983ecfb1e15624f6eff6d31
MD5 hash:
26d4984bef172c5a0b51817673a5edd9
SHA1 hash:
c0ab137c0d73a864b0cdac7558a1a906b5de7b84
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AutoIt
Author:Jean-Philippe Teissier / @Jipe_
Description:AutoIT packer
Rule name:AutoIT_Compiled
Author:@bartblaze
Description:Identifies compiled AutoIT script (as EXE). This rule by itself does NOT necessarily mean the detected file is malicious.
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:UPX
Author:kevoreilly
Description:UPX Unpacker: dump on OEP (original entry point)
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:upx_largefile
Author:k3nr9
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:YahLover
Author:Kevin Falcoz
Description:YahLover

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Loda

Executable exe 2b2cf3626f4d79fa2b10001f024b86677c63e2381f0923331924d26b1ee676ba

(this sample)

Comments