MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 48290438a9422960ffc63c428a9645de43d2a9a0cda9f35b0d37ac32a232ccc7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 48290438a9422960ffc63c428a9645de43d2a9a0cda9f35b0d37ac32a232ccc7
SHA3-384 hash: bae5878aa6a65e6b03a7a1890b2dfcd682ba230573f358a1a4039421303a5f7a22ad3421b3e77695ba2573603eebb08a
SHA1 hash: 2fe466bd440755c566d0155449c596a47ab537ec
MD5 hash: acbde86c9bef655fef24a316a7ee0bc8
humanhash: zulu-saturn-glucose-enemy
File name:IMG6690-05-2020 BANK ORDER SCAN COPIES.rar
Download: download sample
Signature Loki
File size:982'156 bytes
First seen:2020-05-18 12:52:09 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:soUp7/IHtgecfdy7BdTO8TVqCOr7QwUVENm32v:sxpUH9VU8JqXHQwULmv
TLSH 1F2533BDDC8945B0D5800B0896D39ACD570688F704D3A26C489F993798FE17EB39E63E
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail.eldorado.com.uy
Sending IP: 190.64.204.54
From: Claudia Mendaro <cmendaro@eldorado.com.uy>
Subject: Fwd: WIRE ORDER No 6942 *BST E010-07976
Attachment: IMG6690-05-2020 BANK ORDER SCAN COPIES.rar (contains "IMG6690-05-2020 BANK ORDER SCAN COPIES.exe")

Loki C2:
http://mecharnise.ir/da9/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 13:36:19 UTC
File Type:
Binary (Archive)
Extracted files:
27
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 48290438a9422960ffc63c428a9645de43d2a9a0cda9f35b0d37ac32a232ccc7

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments