MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f3de26400e8356bc145a5029f8b3636928276339cf5b9d92bfda8bd8cfd6d7f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f3de26400e8356bc145a5029f8b3636928276339cf5b9d92bfda8bd8cfd6d7f
SHA3-384 hash: 1af3ed77d47a75285196f8832c9113f9c28c3472d9c3135eb386025f219ef2b4c519e5a8230043f19d19ea4af0edab90
SHA1 hash: c972622a02d0c7c8ca87c5d79bb0a16ada1e2019
MD5 hash: 3382d1799a1f98e8c6b27d9cb40be109
humanhash: gee-earth-helium-nuts
File name:IMPORT LOAN PAYMENT.gz
Download: download sample
Signature Loki
File size:395'878 bytes
First seen:2020-10-21 10:09:35 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:Zn66IXgwqsrS4g1DpBBI43MHgfq9cOHpe:M6IXgnsrl8dBBh/fqc9
TLSH 6C84239A8031588868C9C7322DA5C1FFA75CFEA3539C8D8C96E55CE3ABB54A5CCF14C4
Reporter abuse_ch
Tags:gz HSBC Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.tuguhotels.com
Sending IP: 103.219.251.235
From: HSBC BANK <saigonsan@tuguhotels.com>
Reply-To: inbox@domain.com
Subject: IMPORT LOAN PAYMENT CHASER Our Ref: CILJAK164769 - Ref:[TRDA72142138313]
Attachment: IMPORT LOAN PAYMENT.gz (contains "IMPORT LOAN PAYMENT.exe")

Loki C2:
http://easydriverservice.com/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-21 09:18:06 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 5f3de26400e8356bc145a5029f8b3636928276339cf5b9d92bfda8bd8cfd6d7f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments