MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a89e368ecf059536c57d4585fced393df12f198f037f6340207c3ef2fb57465f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a89e368ecf059536c57d4585fced393df12f198f037f6340207c3ef2fb57465f
SHA3-384 hash: 3f16913fd84b595254ad0264b9988fc0f845abb2ed8e758f85218c615ba7268a10f214a1a54021924cf8a26d2d5c2a1a
SHA1 hash: 3c9086a3726928fe213b43c88f8beed4ef561951
MD5 hash: a0de3a2de4dde7a111596f782fad1cd7
humanhash: uniform-july-blossom-charlie
File name:IMG_005938582857265224_PDF.iso
Download: download sample
Signature Loki
File size:1'243'136 bytes
First seen:2020-05-21 16:03:27 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:ftb20pkaCqT5TBWgNQ7ac/XIWQ+OHFS7CBXpW6A:cVg5tQ7acz2D65
TLSH 3645AE1223DF8261CF7E51737A15B741AE7BFC1505A0B4BB2F98C93CAA201215E1E66F
Reporter abuse_ch
Tags:CaixaBank iso Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: vxsys-smtpclusterma-06.srv.cat
Sending IP: 46.16.60.157
From: Contact Center Confirming <contact_center_confirming@caixabank.com>
Subject: Advice payment at maturity CaixaConfirming
Attachment: IMG_005938582857265224_PDF.iso (contains "IMG_005938582857265224_PDF.exe")

Loki C2:
http://maylnk.ml/DBY/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-22 03:15:14 UTC
File Type:
Binary (Archive)
Extracted files:
12
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

iso a89e368ecf059536c57d4585fced393df12f198f037f6340207c3ef2fb57465f

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments