MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 189a7188cd8ed712ed0e0035c38b43da34a6df285e2d62b7c1f9206bf7f43a4b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 189a7188cd8ed712ed0e0035c38b43da34a6df285e2d62b7c1f9206bf7f43a4b
SHA3-384 hash: a5a99e02583d5d1cbe2ccd4b8edfc6700996b60fd610ed860412cf85360329c3274c4a67e4105fe35b668644bfc1e24b
SHA1 hash: 2409e4ba63f665ffb06911ebc2addddcbf932b36
MD5 hash: bad049d910130812129a8b91336652e8
humanhash: yellow-april-seventeen-alabama
File name:KKBK201672858278.gz
Download: download sample
Signature Loki
File size:415'053 bytes
First seen:2020-06-16 05:30:34 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:2QgDg9MoZN7ifk1JZBsbl/1oIYbXOW9VafeMtMj5qO:2QgEXwixW/OIYbhoe7j5qO
TLSH D89423C8B5D6CF96BE70CD7FE0F916D228EAF2906D01BFC4D035619416146CCAA236A6
Reporter abuse_ch
Tags:geo gz IND Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: ns2.agrobogautama.co.id
Sending IP: 122.102.40.26
From: KOTAK BANK <Accounts@kotakbank.com>
Subject: InterBank-NEFT Transfer Credit Alert
Attachment: KKBK201672858278.gz (contains "SQ079375.exe")

Loki C2:
http://sportsgroup-hk.com/six/bryt2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-16 05:32:04 UTC
AV detection:
36 of 48 (75.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 189a7188cd8ed712ed0e0035c38b43da34a6df285e2d62b7c1f9206bf7f43a4b

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments