MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0592e17a1580693a9afe1e81956ac3d0dce739c6c33254ce354c96d3a00a77e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0592e17a1580693a9afe1e81956ac3d0dce739c6c33254ce354c96d3a00a77e0
SHA3-384 hash: 2e92807c7e45f33ba7809529f35be73a7aac89472e5e65a04f30424d9199e2aa99fdaaa4396d63b2c770fee12dd1f340
SHA1 hash: 8830ac96ce0fe462587296904d9c6f8b20c14b96
MD5 hash: ca15012344d9c439113d2ce0c28e73d3
humanhash: skylark-blossom-pip-alabama
File name:Scan2359.gz
Download: download sample
Signature Loki
File size:352'412 bytes
First seen:2020-07-03 09:54:30 UTC
Last seen:2020-07-08 10:17:43 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:2SpisdtKOBwFRYPdZnw5BUimqwArQbutX7QLqQ17ZaaPPPe3VtYRCYt6Fk2/71pg:zMsrKOwKdFw5BtmvATtXEGOUaPnSY/3D
TLSH 527423BC6F290E275FE0862222F9362D365D46FCAEA6CDE90F34CB8A6451DC0152D473
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
7
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-03 09:27:03 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 0592e17a1580693a9afe1e81956ac3d0dce739c6c33254ce354c96d3a00a77e0

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments