🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89f6c08fa045d14eb73a0992145a724bc34d531d7af3dcc4901a1b7c7833aede. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 17


Intelligence 17 IOCs 1 YARA 5 File information Comments

SHA256 hash: 89f6c08fa045d14eb73a0992145a724bc34d531d7af3dcc4901a1b7c7833aede
SHA3-384 hash: 7bc678a751b88054b58729b02cfcf162bba3f5bc691413526a5c316a5a812b0bc666f9807a3fae5206fd7eaa2966927e
SHA1 hash: dd971d09f94dbd77735a07fc297dd2836fd94616
MD5 hash: 3d639a627186e77730ff2d1294df49a3
humanhash: florida-idaho-fruit-summer
File name:3D639A627186E77730FF2D1294DF49A3.exe
Download: download sample
Signature Loki
File size:681'472 bytes
First seen:2026-08-25 02:25:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'239 x AgentTesla, 20'492 x Formbook, 12'372 x SnakeKeylogger)
ssdeep 3072:sAf07/cWVdNFWe3GthMEIO3jmbaFaexjbzyJlPgPg:+5Vdn7WthLDxjbQs
TLSH T172E4BD0E83954667ED206972AD6E7B41C2A51A3E7C63F7B9FF183243B9213C4453363A
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon ecf2b212dbc8cccb (4 x AgentTesla, 2 x Formbook, 1 x SnakeKeylogger)
Reporter abuse_ch
Tags:exe Loki


Avatar
abuse_ch
Loki C2:
http://niskioglasi.rs/test2/Panel/fre.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://niskioglasi.rs/test2/Panel/fre.php https://threatfox.abuse.ch/ioc/1886606/

Intelligence


File Origin
# of uploads :
1
# of downloads :
186
Origin country :
NL NL
Vendor Threat Intelligence
Malware configuration found for:
LokiBot RoboSki
Details
Result
Verdict:
Malware
Maliciousness:

Behaviour
Launching a process
Searching for synchronization primitives
Сreating synchronization primitives
Creating a window
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
agenttesla base64 obfuscated overlay packed remcos
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-08-22T09:26:00Z UTC
Last seen:
2026-08-26T18:25:00Z UTC
Hits:
~10
Malware family:
Malicious Packer
Verdict:
Malicious
Result
Threat name:
Lokibot
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Found malware configuration
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected aPLib compressed binary
Yara detected Lokibot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963125 Sample: VzgFLM7O6n.exe Startdate: 25/08/2026 Architecture: WINDOWS Score: 100 34 niskioglasi.rs 2->34 38 Suricata IDS alerts for network traffic 2->38 40 Found malware configuration 2->40 42 Malicious sample detected (through community Yara rule) 2->42 44 9 other signatures 2->44 8 VzgFLM7O6n.exe 9 2->8         started        12 WkYZdww.exe 3 2->12         started        signatures3 process4 file5 26 C:\Users\user\AppData\Roaming\WkYZdww.exe, PE32 8->26 dropped 28 C:\Users\user\...\WkYZdww.exe:Zone.Identifier, ASCII 8->28 dropped 30 C:\Users\user\AppData\Local\Temp\tmp89.tmp, XML 8->30 dropped 32 C:\Users\user\AppData\...\VzgFLM7O6n.exe.log, ASCII 8->32 dropped 46 Uses schtasks.exe or at.exe to add and modify task schedules 8->46 48 Injects a PE file into a foreign processes 8->48 50 Unusual module load detection (module proxying) 8->50 14 VzgFLM7O6n.exe 55 8->14         started        18 schtasks.exe 1 8->18         started        20 VzgFLM7O6n.exe 8->20         started        52 Antivirus detection for dropped file 12->52 54 Multi AV Scanner detection for dropped file 12->54 56 Tries to steal Mail credentials (via file registry) 12->56 22 WkYZdww.exe 12->22         started        signatures6 process7 dnsIp8 36 niskioglasi.rs 212.200.255.48, 49698, 49713, 49714 TELEKOM-ASRS Serbia 14->36 58 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 14->58 60 Tries to steal Mail credentials (via file / registry access) 14->60 62 Tries to harvest and steal ftp login credentials 14->62 64 Tries to harvest and steal browser information (history, passwords, etc) 14->64 24 conhost.exe 18->24         started        signatures9 process10
Verdict:
inconclusive
YARA:
9 match(es)
Tags:
.Net Executable Managed .NET PE (Portable Executable) PE File Layout SOS: 0.18 Win 32 Exe x86
Threat name:
Win32.Trojan.AgentTesla
Status:
Malicious
First seen:
2026-08-22 14:22:22 UTC
File Type:
PE (.Net Exe)
Extracted files:
12
AV detection:
23 of 24 (95.83%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
LokiPasswordStealer(PWS) ReZer0
Result
Malware family:
lokibot
Score:
  10/10
Tags:
family:lokibot collection discovery execution persistence spyware stealer trojan
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Checks computer location settings
Executes dropped EXE
Reads user/profile data of web browsers
Family: Lokibot
Malware Config
C2 Extraction:
http://niskioglasi.rs/test2/Panel/fre.php
http://kbfvzoboss.bid/alien/fre.php
http://alphastand.trade/alien/fre.php
http://alphastand.win/alien/fre.php
http://alphastand.top/alien/fre.php
Unpacked files
SH256 hash:
89f6c08fa045d14eb73a0992145a724bc34d531d7af3dcc4901a1b7c7833aede
MD5 hash:
3d639a627186e77730ff2d1294df49a3
SHA1 hash:
dd971d09f94dbd77735a07fc297dd2836fd94616
SH256 hash:
b293342e115dc3903b73459d45d1b958d83c604c271479b975bf22049ecb2466
MD5 hash:
fb702c146d634e5e1088936f40ace6a6
SHA1 hash:
063738db68c90557fb6b29d46fc679eaff6ab2e4
Detections:
CyaxSharp_ReZer0 SUSP_OBF_NET_Eazfuscator_String_Encryption_Jan24
SH256 hash:
8cc8f6d82d589059867f2e321594d59b97759027b508b8d3640ecc8b838a513d
MD5 hash:
80331dc7861da56b488fa68d9202d244
SHA1 hash:
b6a30bdd4dce1782a0b00b38a211d63256c55216
SH256 hash:
a7dfd2c49f3627ad46c6aa05572d314da78938f2a09a8a4f8e3b60efc8d5cebd
MD5 hash:
1f545fd330d2fb49373846219facbe92
SHA1 hash:
ec83a630950a31c3bc260e094145392fe89f546a
Detections:
lokibot win_lokipws_auto win_lokipws_g0 INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients INDICATOR_SUSPICIOUS_GENInfoStealer Lokibot STEALER_Lokibot
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:SUSP_Reversed_Base64_Encoded_EXE_RID3291
Author:Florian Roth
Description:Detects an base64 encoded executable with reversed characters
Reference:Internal Research
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments