MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 580fa8aa467a041f098469b1648ee05237d5c9fb9da1298a76e263f6910f1b2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 580fa8aa467a041f098469b1648ee05237d5c9fb9da1298a76e263f6910f1b2f
SHA3-384 hash: 247a96266fe9393c9f9074a15bcd52283ebde04c151d2bd591da2055aa1c33bbec7e02a5bce9b531fe855bd2d0fea3a4
SHA1 hash: ae21dcd53cfd6a1c50394919eed9078e0125f063
MD5 hash: 0ec0ec3b92f6c8282db8a3e0291159f1
humanhash: king-august-freddie-papa
File name:DHL Shipping Documents.gz
Download: download sample
Signature Loki
File size:118'635 bytes
First seen:2020-04-06 09:43:05 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 3072:MOP3e8ttHOURa65lKf94E7E5JxK/3OU6tsmRA:MIeQchWEF4YWc/p6LA
TLSH 4DC312F923A521C6F3F586869EC2D4268448AA3307AE53910B3C53F7963E60D71C2F76
Reporter abuse_ch
Tags:COVID-19 GuLoader gz Loki


Avatar
abuse_ch
COVID-19 themed malspam distributing GuLoader->Loki:

HELO: mxserver7-out10.masterweb.com
Sending IP: 103.25.223.243
From: Asia_DHL | Express <dhlexpress.billingid@dhl.com>
Subject: DHL Shipping Documents, Invoice and AWB/ Service impact due to\x0a COVID-19 outbreak
Attachment: DHL Shipping Documents.gz (contains "DHL Shipping Documents")

GuLoader payloed URL (Loki):
https://beeps.my/tz/b2_build_encrypted_1E75CB0.bin

Loki C2:
http://audiosv.com/b2/Panel/fre.php (45.252.248.29)

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Androm
Status:
Malicious
First seen:
2020-04-06 10:36:28 UTC
File Type:
Binary (Archive)
Extracted files:
44
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 580fa8aa467a041f098469b1648ee05237d5c9fb9da1298a76e263f6910f1b2f

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments