MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 850935778a4362280adbb3b66421d6fa4156044f8c3d1453eea4eb3d01fecfc5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 850935778a4362280adbb3b66421d6fa4156044f8c3d1453eea4eb3d01fecfc5
SHA3-384 hash: d251b6f8b4017be96be20165259fe7dd36eb98f2e9ec45c1a762ad05935dbd9726845b25eb57894cd72860e49fdd9676
SHA1 hash: 2f101055d2fb3130f63908c7967177b7a3582a9a
MD5 hash: 756dc919b26646ae9380138d65ca8a9f
humanhash: fourteen-rugby-oxygen-jersey
File name:_777504307241.GenesisAWB.PDF.gz
Download: download sample
Signature Loki
File size:352'107 bytes
First seen:2020-10-14 17:19:59 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:EztqH+5Lj8S0oQeoQkeNgzapKKeJtZHra/lIHGKdvdV58GkXhPbUierg80:Mtq0Hr0oQ/6NRqHO/hWdVG9xwl0
TLSH 8F7423D47C4FD43D4BAE89C01B185BDF3048D2A20E24C5787A569F6BC29AD3952E8D78
Reporter abuse_ch
Tags:FedEx gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.tuguhotels.com
Sending IP: 103.219.251.235
From: FedEx CCS (Emirates) <saigonsan@tuguhotels.com>
Subject: RE: [EXTERNAL] : FedEx PRE Notification of Arrival - AWB# 770116605315 // UAE: Need BC23 Confirmation
Attachment: _777504307241.GenesisAWB.PDF.gz (contains "_777504307241.GenesisAWB.PDF.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-14 16:30:46 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 850935778a4362280adbb3b66421d6fa4156044f8c3d1453eea4eb3d01fecfc5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments