MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8ef9fb0d37c0b204859f90c5ec596e441781f35190a7b5d616e0023411fe51d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c8ef9fb0d37c0b204859f90c5ec596e441781f35190a7b5d616e0023411fe51d
SHA3-384 hash: 105de630ea26c4a76f147bfafe0e1dfa606a30479ee6ef2253e0a610b0d4507c4040d2faa97d59ac31f2c711019baf03
SHA1 hash: 02ad219fddc81d5b9a0630e8bee522a1f2759aa3
MD5 hash: 51eea1e29b479c46be42160d14813cca
humanhash: mirror-august-chicken-mike
File name:Invoice 948849.img
Download: download sample
Signature Loki
File size:1'245'184 bytes
First seen:2020-11-06 17:35:01 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:uFNBhZcfwXpUxneVTAtRLIpCZ5pB2/gcg0u/qXR+zeHHX1dyL++Ch0vU:eZc6Uxn9tZDZ5C/gz2gzeHHXuLBvU
TLSH 8745DF207581C072C4B7183000F9D2729E7DFE311FA59AAF739D133A6F646D2A62996F
Reporter abuse_ch
Tags:img Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: fsn110.truehost.cloud
Sending IP: 136.243.73.170
From: Saurabh Kumar<admin@hoslinkagency.com>
Reply-To: <jennie.tonner@cremorne.com.au>
Subject: RE: 23208 // CI & PL (WF-8th Shipment)
Attachment: Invoice 948849.img (contains "inv.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
118
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Androm
Status:
Malicious
First seen:
2020-11-06 12:45:02 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

img c8ef9fb0d37c0b204859f90c5ec596e441781f35190a7b5d616e0023411fe51d

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments