MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92cdd37b5bb5e0e2f49a16496e8f04a3159994e2d705726a019e63f56782e9ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92cdd37b5bb5e0e2f49a16496e8f04a3159994e2d705726a019e63f56782e9ae
SHA3-384 hash: abd4bdfdfe40aeb5211b5b305e0e29f2626ea512de342ddcfdda5f4c267dd6bd6eb28f27a9e72c3fd6a5219030db8747
SHA1 hash: c2599ff70aa59e3a957785fcb90a7e8823c3ade0
MD5 hash: 8fc4920c04fd93f4c0955c417659fbd6
humanhash: bulldog-lemon-december-papa
File name:ID20224011170004382015_REDEMPTION_REKSA DANA BATAVIA DANA LIKUID_pdf.gz
Download: download sample
Signature Loki
File size:394'881 bytes
First seen:2020-11-19 06:49:53 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:66+F0AGAbCO88hm8aqySdAqV8h0DPnJOmnpeEAeQh6zqtOYtGo+ka1Md5:6YWTFaWVV8qDPJOkgEq6zS5Qn+
TLSH 9E84231FF307D329116EABC46C760E764644E76A406B61FB28BCFF4306638AA54B71D8
Reporter abuse_ch
Tags:gz HSBC Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.interteknis.co.id
Sending IP: 103.247.10.219
From: HSBC Custody e-Statement <yetty@interteknis.co.id>
Subject: Your Mutual Fund e-Statement [ID20224011170004382015
Attachment: ID20224011170004382015_REDEMPTION_REKSA DANA BATAVIA DANA LIKUID_pdf.gz (contains "ID20224011170004382015_REDEMPTION_REKSA DANA BATAVIA DANA LIKUID_pdf.exe")

Loki C2:
http://legalpath.in/xxx/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.Loki
Status:
Malicious
First seen:
2020-11-19 06:50:08 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 92cdd37b5bb5e0e2f49a16496e8f04a3159994e2d705726a019e63f56782e9ae

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments