MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c5571f6ddf788b1cc065cc814a0a2778224328eb28042abed7f45cd34d72c998. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c5571f6ddf788b1cc065cc814a0a2778224328eb28042abed7f45cd34d72c998
SHA3-384 hash: 76ccb7d4332f74eb09776cddf74c05d8925304f87df1f4902f348342f94631cf1906f0c45a4adfc902fe3058d0a589d7
SHA1 hash: 8339f24a030fcfaf9a9b71b8c192d5c30bab85ca
MD5 hash: f0c86e2e9f7ab48c9c844d5c5117f9e4
humanhash: spaghetti-winter-bravo-seven
File name:rfq_04885546.pdf.gz
Download: download sample
Signature Loki
File size:480'249 bytes
First seen:2020-07-13 11:59:31 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:yIPYvkY+KLx6PgoWXHswQ+EdyiyUxf9NadGFOSM/:yIVh2MyHswQ+U1Aa2
TLSH 8BA42388FC247F39A4B65B8B3359399B3212262C61276124E60643D97E6EF6173F250F
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: cpanel14.dnscpanel.com
Sending IP: 94.126.169.114
From: Eslam <nss.marketing@talebgroup.com>
Subject: Fwd: Request for the Quotation
Attachment: rfq_04885546.pdf.gz (contains "rfq_04885546.pdf.exe")

Loki C2:
http://kovachevpress.com/docsx/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-07-13 12:01:04 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz c5571f6ddf788b1cc065cc814a0a2778224328eb28042abed7f45cd34d72c998

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments