MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a313e5c478cd35a756a53d21bcf636896193d7a94c8586122368f25fd6c275c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4a313e5c478cd35a756a53d21bcf636896193d7a94c8586122368f25fd6c275c
SHA3-384 hash: 20054d040eac84ce76cc8fcc72d7e7096c071bd60d589c7ec7bfbedfe5a658da0f4de18af73212338b7e777d0453b448
SHA1 hash: 18c61847c9f1d0c7a8338c6c525b2a550829e55a
MD5 hash: c5460ad9ba301fa771f877f1ed936e16
humanhash: hawaii-failed-pasta-glucose
File name:FP Inv BPNIR00015564.pdf.gz
Download: download sample
Signature Loki
File size:357'095 bytes
First seen:2020-10-16 14:05:35 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:ZqUKrTKBy56YOSVFqAYUa2b/F0PAiNrPRPPR5zbOF1PyqnTZCM7CDyVxgHgP:lo6oFqAsp9J5KnWHgP
TLSH 4074235BCAFBCDD7A83230355BB01EA05319215F1432BAADEF102175AEEE660B4DED11
Reporter abuse_ch
Tags:DHL gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.tuguhotels.com
Sending IP: 103.219.251.235
From: DHL Billing Parcel <saigonsan@tuguhotels.com>
Subject: RE: Outstanding Invoice AWB00015564 with the Requested Paperwork
Attachment: FP Inv BPNIR00015564.pdf.gz (contains "FP Inv BPNIR00015564.pdf.exe")

Loki C2:
http://venitronics.com/oo/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Strictor
Status:
Suspicious
First seen:
2020-10-16 14:07:05 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 4a313e5c478cd35a756a53d21bcf636896193d7a94c8586122368f25fd6c275c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments