MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9c50d267e39a9268264624b050ea8ba1fa29f014ca0bb21222d6a8d715b28d3c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 16


Intelligence 16 IOCs 1 YARA 4 File information Comments

SHA256 hash: 9c50d267e39a9268264624b050ea8ba1fa29f014ca0bb21222d6a8d715b28d3c
SHA3-384 hash: 773388e028cdd2d35f1e78384b48026dec7860b536ccd83a69c14ea1a2d0f4a798863e09f5729816bd2f522666080aaa
SHA1 hash: 805f365ca684589e5b1f466bd5f10362c274c0f5
MD5 hash: 4f88c112e23f2e7bb169801c388bb0bd
humanhash: wyoming-indigo-green-nitrogen
File name:4F88C112E23F2E7BB169801C388BB0BD.exe
Download: download sample
Signature Loki
File size:594'944 bytes
First seen:2026-02-12 05:10:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6a5b34ba09a4b1dcfa5c7ddce3109ef9 (1 x Loki)
ssdeep 12288:Pdo8eOaMXdoFDWDemKoW2vFpEGWa9ceVV118jc3+a03jl6c:VzeyXdoFDWDemKoW2vFp6a9/ZT0Tl
Threatray 1 similar samples on MalwareBazaar
TLSH T1D9C48E3E61BC4A33D423267ACE3B46699932BDD13B7859892BF81CCC9F74341B536192
TrID 52.9% (.EXE) Win32 Executable Delphi generic (14182/79/4)
16.8% (.EXE) Win32 Executable (generic) (4504/4/1)
7.7% (.EXE) Win16/32 Executable Delphi generic (2072/23)
7.5% (.EXE) OS/2 Executable (generic) (2029/13)
7.4% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 08e2c1e0b8c2fac0 (1 x Loki)
Reporter abuse_ch
Tags:exe Loki


Avatar
abuse_ch
Loki C2:
http://nonny11.xyz/sol/fre.php

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
http://nonny11.xyz/sol/fre.php https://threatfox.abuse.ch/ioc/1746411/

Intelligence


File Origin
# of uploads :
1
# of downloads :
166
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
_9c50d267e39a9268264624b050ea8ba1fa29f014ca0bb21222d6a8d715b28d3c.exe
Verdict:
No threats detected
Analysis date:
2026-02-12 05:12:00 UTC
Tags:
delphi

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
infosteal autorun delphi
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Reading critical registry keys
Launching a service
Changing a file
DNS request
Connection attempt
Sending an HTTP POST request
Moving a file to the %AppData% subdirectory
Enabling the 'hidden' option for recently created files
Unauthorized injection to a recently created process
Unauthorized injection to a recently created process by context flags manipulation
Stealing user critical data
Enabling autorun by creating a file
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-02-09T08:10:00Z UTC
Last seen:
2026-02-12T04:38:00Z UTC
Hits:
~10
Detections:
Backdoor.Win32.Agent.sb Trojan.Win32.Kryptik.sb HEUR:Backdoor.Win32.Generic
Result
Threat name:
Lokibot
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to detect sleep reduction / modifications
Creates / moves files in alternative data streams (ADS)
Deletes itself after installation
Drops VBS files to the startup folder
Found malware configuration
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Sigma detected: Drops script at startup location
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Yara detected aPLib compressed binary
Yara detected Lokibot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1868097 Sample: ZyEstRH04D.exe Startdate: 12/02/2026 Architecture: WINDOWS Score: 100 35 nonny11.xyz 2->35 39 Suricata IDS alerts for network traffic 2->39 41 Found malware configuration 2->41 43 Malicious sample detected (through community Yara rule) 2->43 47 9 other signatures 2->47 8 ZyEstRH04D.exe 4 2->8         started        12 wscript.exe 1 2->12         started        signatures3 45 Performs DNS queries to domains with low reputation 35->45 process4 file5 29 C:\Users\user\...\jkngjnkjngfoikjnlf.exe, PE32 8->29 dropped 31 C:\...\jkngjnkjngfoikjnlf.exe:Zone.Identifier, ASCII 8->31 dropped 57 Creates / moves files in alternative data streams (ADS) 8->57 59 Contains functionality to detect sleep reduction / modifications 8->59 14 jkngjnkjngfoikjnlf.exe 1 8->14         started        18 jkngjnkjngfoikjnlf.exe 8->18         started        61 Windows Scripting host queries suspicious COM object (likely to drop second stage) 12->61 signatures6 process7 file8 33 C:\Users\user\...\fohndgoouhvsisffsffs.vbs, ASCII 14->33 dropped 63 Maps a DLL or memory area into another process 14->63 20 jkngjnkjngfoikjnlf.exe 59 14->20         started        25 jkngjnkjngfoikjnlf.exe 14->25         started        65 Multi AV Scanner detection for dropped file 18->65 67 Drops VBS files to the startup folder 18->67 69 Deletes itself after installation 18->69 signatures9 process10 dnsIp11 37 nonny11.xyz 3.238.30.69, 49693, 49695, 49697 AMAZON-AESUS United States 20->37 27 C:\Users\user\AppData\...\31437F.exe (copy), PE32 20->27 dropped 49 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 20->49 51 Tries to steal Mail credentials (via file / registry access) 20->51 53 Tries to harvest and steal ftp login credentials 20->53 55 Tries to harvest and steal browser information (history, passwords, etc) 20->55 file12 signatures13
Gathering data
Threat name:
Win32.Backdoor.Multiverze
Status:
Malicious
First seen:
2026-02-09 13:11:47 UTC
AV detection:
27 of 38 (71.05%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
lokipasswordstealer(pws)
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
9c50d267e39a9268264624b050ea8ba1fa29f014ca0bb21222d6a8d715b28d3c
MD5 hash:
4f88c112e23f2e7bb169801c388bb0bd
SHA1 hash:
805f365ca684589e5b1f466bd5f10362c274c0f5
SH256 hash:
d00c0f21d16bc5f4c276f9ed893c7fd986245f442c28ba47cd89118cf97bf30d
MD5 hash:
18ca5d88d47b937873d6582233a6905f
SHA1 hash:
8c02a0092508c1e1eca6b72718eb9358f21cefda
Detections:
win_lokipws_g0 win_lokipws_auto lokibot STEALER_Lokibot SUSP_XORed_URL_In_EXE Lokibot INDICATOR_SUSPICIOUS_Binary_References_Browsers INDICATOR_SUSPICIOUS_EXE_Referenfces_File_Transfer_Clients INDICATOR_SUSPICIOUS_GENInfoStealer
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BobSoftMiniDelphiBoBBobSoft
Author:malware-lu
Rule name:Borland
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments