MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c3056908bd9cffa498c9ddbbbf030f1691b7438564eaa5bc1cb7812808ec1d7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2c3056908bd9cffa498c9ddbbbf030f1691b7438564eaa5bc1cb7812808ec1d7
SHA3-384 hash: 843b92d036133a46262ed1ad8267137131eafffbb6bbfd5f0b4685b9ce98ea697c3e1569a557674e85bc887647cd6d21
SHA1 hash: 3df51efae1033f31dd439ad69249ac8af13f4b27
MD5 hash: 20fc7f6ff67521094964e33331f6daf8
humanhash: rugby-arkansas-sweet-leopard
File name:A4580809.gz
Download: download sample
Signature Loki
File size:350'586 bytes
First seen:2020-07-02 07:10:39 UTC
Last seen:2020-07-02 10:12:08 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:GzcPlgir1uVW1AGj+ZvaWmWpSqapygMuXI2qO5YIC5LzY/8pMDotMdh9OCm3v:GzcJr1uVWhj+ZZpSqakgpbYFE8DEhMCm
TLSH 6B742309AC48AB4B1C25B38E2579499978930F3A9934FCC1A59B9B7B70012BF4B8DD53
Reporter jarumlus
Tags:Loki

Intelligence


File Origin
# of uploads :
5
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-02 07:12:05 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 2c3056908bd9cffa498c9ddbbbf030f1691b7438564eaa5bc1cb7812808ec1d7

(this sample)

  
Dropped by
Loki
  
Delivery method
Distributed via e-mail attachment

Comments