MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0989cfbcc615c467403bbabd1d134f8fe9472aacc6ebb4716ebfc99de120f950. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0989cfbcc615c467403bbabd1d134f8fe9472aacc6ebb4716ebfc99de120f950
SHA3-384 hash: a640a476d0435273f97a32dee4c50770606e052bba3e6f265afe5dea5f7ef5a763beaa74a7109abe73f0edb38a90ff5b
SHA1 hash: 3bad631ea78e729592a85c8ffedc6004040ef4a9
MD5 hash: 886a4abfc47422feabb6ca86f71402f7
humanhash: march-potato-saturn-victor
File name:RFQ Global Trading SPA 01.img
Download: download sample
Signature Loki
File size:780'288 bytes
First seen:2020-07-16 18:42:14 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:17Gnjl8twq80z7GQI5AyBO/nFVtvnDBpqJXWueQbXhWA+x+Fv0nqfzUBen0OkUO:xGj8wq8NzO/Dtvny9L8x+QaS
TLSH 12F49D00CA296CE7DEDD56FAC4945084E7F9CC368D0EE64BA74938D9DF373A1A503286
Reporter abuse_ch
Tags:img Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: General-Trading.com
Sending IP: 192.3.3.154
From: Angelo Rota <info@General-Trading.com>
Subject: RE: Price Offer and Request for Quotation-General Trading SPA
Attachment: RFQ Global Trading SPA 01.img (contains "RFQ Global Trading SPA 01img.com")

Loki C2:
http://fixerrors-mail.cf/holy/five/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.LokiBot
Status:
Malicious
First seen:
2020-07-16 18:44:06 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

img 0989cfbcc615c467403bbabd1d134f8fe9472aacc6ebb4716ebfc99de120f950

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments