MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8c5023f56fc3c7295aec884658def3acb791cf686e25799c759119fc3a572a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e8c5023f56fc3c7295aec884658def3acb791cf686e25799c759119fc3a572a5
SHA3-384 hash: b70927a1118b9440f49f14443cfdf86647c108267c08af5280ff0112d5687fa2cc1fabf5cfbed4d7916677041339fe6c
SHA1 hash: a090b6bec995a08f649c7014499a9c4fd619d6ce
MD5 hash: d141c2e0215c72162da99e399456cdf9
humanhash: white-florida-west-october
File name:New Order 00097532_PDF.gz
Download: download sample
Signature Loki
File size:407'276 bytes
First seen:2020-10-15 12:16:37 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:YPO2xPShIcF3YowEjxdxF7yFH4IMQSOVpoDNYJqKF89svzpc+r0M2z+oOltpYTsd:8QF6Ejx5uZ4FQSsoJwTQM2yjKTLy
TLSH A084233F4BDC91F8A399A1C311D4E4A275A6FE77A62DCCE1639B0A186D0D9402CF7B05
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: thuthe8668
Sending IP: 103.90.224.94
From: Purchase Manager <purchase.hyd@lasershaving.in>
Reply-To: Purchase Manager <ricknicolas.aol@hotmail.com>
Subject: New Purchase Order
Attachment: New Order 00097532_PDF.gz (contains "New Order 00097532_PDF.exe")

Loki C2:
http://195.69.140.147/.op/cr.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.LokiBot
Status:
Malicious
First seen:
2020-10-15 09:10:04 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz e8c5023f56fc3c7295aec884658def3acb791cf686e25799c759119fc3a572a5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments