MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 21a8d79d6ad823c193dcb792b6da0a6020b123e9a572220ce287671f7837f61b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 21a8d79d6ad823c193dcb792b6da0a6020b123e9a572220ce287671f7837f61b
SHA3-384 hash: ba1be74b0a1ba18bcc53eb44a9ace52a213194126318c7b6abe2a6a8e658f073d25127c7a8ae05f3eca1948c38229c82
SHA1 hash: b1cb5106a488404b919c73c49d6f24b127da5a4f
MD5 hash: 48f52bfb8297d92d19eb83e44a0376f8
humanhash: moon-juliet-ohio-salami
File name:file-0271144_pdf.gz
Download: download sample
Signature Loki
File size:475'855 bytes
First seen:2020-07-01 04:25:31 UTC
Last seen:2020-07-01 09:19:31 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:yMH1eO7js6oPuX1OWF/7Q1F6QLzasA1q8OfLoKHcqCFxVM34Mirq/QNnBGdWnx91:9VEYkP5LesAROPEJM3FDQN3LP9YwVn
TLSH E2A423DBD6181CE363F8E85C8FD3A73665C082852A46097D14062A0FECCDE77929D8BD
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
3
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-01 03:01:35 UTC
AV detection:
24 of 29 (82.76%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 21a8d79d6ad823c193dcb792b6da0a6020b123e9a572220ce287671f7837f61b

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments