Loki-Bot from malspam .iso
Files: File name: GMT_20190319060920563.com.exe MD5: 3902567752c57bf36107a01990a5cc92 SHA256: 5986a088e86b2d169b3234aadf47ecddce1b8ac24e050b1423ef14ed5f06e609 Filesize: 446464 bytes File name: GMT_20190319060920563.iso MD5: c2dbe612409ef3dffded940c99cdac66 SHA256: 660e9d2de6f0223c50dfdfe512984f6a8f8400facebbca62db941a2566672458 Filesize: 507904 bytes File name: objectfrabjous.exe MD5: 89ca09b33506f659a39f8bed88103d55 SHA256: b70a7ef290cca5af3631d40e4253dd53ee8da6c8a32fe3a2e563ca27c88932b6 Filesize: 446464 bytes File name: objectfrabjous.vbs MD5: 33a60c46d369c821118edd398c45f949 SHA256: 42bc0ecf7ed5710d8c7417b19c6605c7c6cec2d6b43e9f765922bde1f3bb1339 Filesize: 110 bytes Download (password: malware) URLs: hxxp://gentography[.]ml/david/Panel/five/fre.php hxxp://gentography[.]ml/david/Panel/five/PvqDq929BSx_A_D_M1n_a.php IPs: 104.27.191.40 (cloudflare) Details: This sample caught my eye as it has similar exploit behavior to the REMCOS Rat I analyzed prev...