MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 850935778a4362280adbb3b66421d6fa4156044f8c3d1453eea4eb3d01fecfc5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 850935778a4362280adbb3b66421d6fa4156044f8c3d1453eea4eb3d01fecfc5 |
|---|---|
| SHA3-384 hash: | d251b6f8b4017be96be20165259fe7dd36eb98f2e9ec45c1a762ad05935dbd9726845b25eb57894cd72860e49fdd9676 |
| SHA1 hash: | 2f101055d2fb3130f63908c7967177b7a3582a9a |
| MD5 hash: | 756dc919b26646ae9380138d65ca8a9f |
| humanhash: | fourteen-rugby-oxygen-jersey |
| File name: | _777504307241.GenesisAWB.PDF.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 352'107 bytes |
| First seen: | 2020-10-14 17:19:59 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 6144:EztqH+5Lj8S0oQeoQkeNgzapKKeJtZHra/lIHGKdvdV58GkXhPbUierg80:Mtq0Hr0oQ/6NRqHO/hWdVG9xwl0 |
| TLSH | 8F7423D47C4FD43D4BAE89C01B185BDF3048D2A20E24C5787A569F6BC29AD3952E8D78 |
| Reporter | |
| Tags: | FedEx gz Loki |
abuse_ch
Malspam distributing Loki:HELO: server.tuguhotels.com
Sending IP: 103.219.251.235
From: FedEx CCS (Emirates) <saigonsan@tuguhotels.com>
Subject: RE: [EXTERNAL] : FedEx PRE Notification of Arrival - AWB# 770116605315 // UAE: Need BC23 Confirmation
Attachment: _777504307241.GenesisAWB.PDF.gz (contains "_777504307241.GenesisAWB.PDF.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-14 16:30:46 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.