MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54c1a2aabcd252f42385c5892f6c119bfbbdcc3d4a9826bc4350895b7cd700b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 54c1a2aabcd252f42385c5892f6c119bfbbdcc3d4a9826bc4350895b7cd700b0
SHA3-384 hash: d541892b0e723d034155f551ac5879f925295554216b415078bb4c1d3bf9d703ac9f3f3de77200bb8784706297dbd399
SHA1 hash: 9491c1b87d5744012b046122356356192324dab9
MD5 hash: 7417df4f0e5b66399894684a77fe869f
humanhash: golf-cat-zulu-ten
File name:INV-SG19100009 SG191000008_PAST_DUE.zip
Download: download sample
Signature Loki
File size:370'795 bytes
First seen:2020-08-03 07:00:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:BllLAm2CRdM+rbw/lJJC1u6zlZKMoHvZhM0QBZv3gzGOfyUW76PhG1zGgvyZn4lx:Bcm3d3rU/lJJhqZ9WKxzgzbfB01zaZgn
TLSH EE742377A5AAC3EF580AB111890F8F5FFA3ED9FDA82619231B117B713836951328C464
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: pkz55-3-spamexpert3.hoster.kz
Sending IP: 185.113.132.58
From: n.shaimerdenov@saem-pvl.kz
Subject: *Overdue* urgent payment follow up-2nd Reminder- PO SG19100009
Attachment: INV-SG19100009 SG191000008_PAST_DUE.zip (contains "INV-SG19100009 & SG191000008_PAST_DUE.exe")

Loki C2:
http://sieqwarteg.com/chief/chief2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-08-03 06:00:09 UTC
AV detection:
26 of 47 (55.32%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 54c1a2aabcd252f42385c5892f6c119bfbbdcc3d4a9826bc4350895b7cd700b0

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments