MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d151ed7207ac9ea577320abd912af1e4c1b57651afd4a78c1a0c39e20591ef41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d151ed7207ac9ea577320abd912af1e4c1b57651afd4a78c1a0c39e20591ef41
SHA3-384 hash: 49bbb248479f747614cb9d866ef60a977ba19fcf7c6d2e0031629ada354d288d6ab0eccfe409b5be4eb62c0bdc83ab03
SHA1 hash: 7fa0de79a4e3033fe0eef5a68f59d7e6ae8f07c3
MD5 hash: dee7c73ed021d3f5b613c2eaf713d35a
humanhash: mobile-helium-alaska-winter
File name:Doc00638832664.img
Download: download sample
Signature Loki
File size:1'966'080 bytes
First seen:2021-01-14 20:00:59 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:LimVsKS6A/I80w/n6SFYtCQ42NhG8Lh8Ft2kOag7wyl0y2/1eAGnK/+VqSKOlBdV:LPsj080k/itCQ44Gchk2Y
TLSH D095D658F74073BDF55AB87945340F70AA5CAD66534A920EF00330A99A3D4D68EEFCE2
Reporter abuse_ch
Tags:DHL ESP geo img Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: smarthost1.gohsphere.com
Sending IP: 173.0.129.225
From: Gerente de carga de DHL <facturacion.mx@dhl.com>
Subject: nueva notificación de envío de DHL
Attachment: Doc00638832664.img (contains "Doc00638832664.PDF____________________.bat")

Loki C2:
http://51.195.53.221/p.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-01-14 20:01:07 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

img d151ed7207ac9ea577320abd912af1e4c1b57651afd4a78c1a0c39e20591ef41

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments