MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71c32287e23049bae9aca448f130f8012611c9e86410bc3213b7b2cab26c5ae5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 71c32287e23049bae9aca448f130f8012611c9e86410bc3213b7b2cab26c5ae5
SHA3-384 hash: e35f968391d6a10fc6c161df5e1331fd3b4a533655a61ced1e50e6390cbc5d537b049c0d6785edfa90ddea74584e3df5
SHA1 hash: 10568b31b8ab32e93e7398cfd0f83263bb2ed177
MD5 hash: e3517659ed34caa6c3a132a30234a39a
humanhash: early-monkey-vermont-rugby
File name:Factory nnew purchase order 2020.iso
Download: download sample
Signature Loki
File size:296'960 bytes
First seen:2020-05-04 20:30:49 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:MEbEKnHPZPD4mf4wlZlIANCx6H/ylbnqeHjOlY5c/h:MePdx4w6ANJadnFwYE
TLSH 8254ADA52BE48C2FCAEDC5B4F49018084333D29B9561F781FDDCE0744F87B66696A24B
Reporter abuse_ch
Tags:iso Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: bahra-cables.com
Sending IP: 185.222.58.101
From: Haitham Shaher Kattabeh <haitham.kattabeh@bahra-cables.com>
Subject: RE: factory New Order
Attachment: Factory nnew purchase order 2020.iso (contains "Factory nnew purchase order 2020.exe")

Loki C2:
http://bubuyayatoolslog.ir/contnient-eight.com/los/panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-04 05:22:03 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
16 of 30 (53.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

iso 71c32287e23049bae9aca448f130f8012611c9e86410bc3213b7b2cab26c5ae5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments