MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3c80a7d1d549977570a966c905cf35fddec406dba4caebf2dd7782a06a2de30e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3c80a7d1d549977570a966c905cf35fddec406dba4caebf2dd7782a06a2de30e
SHA3-384 hash: b360a92f4db7846521ce7ec37c67e79438479c57f44a8b43a0f7fb7dca48e9b1ff53c7b5838fcc257b4997ba7fb538fc
SHA1 hash: 6fbfa45a9427c94ab0b0ff86d95992b8ed1c6b90
MD5 hash: 47776362d41dff2feb679a6dd9745ba7
humanhash: purple-lactose-pizza-carpet
File name:Ordine N. OR-0610.pdf.gz
Download: download sample
Signature Loki
File size:363'173 bytes
First seen:2020-06-10 11:35:34 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:2JROhlvHANOIVaxXDF+94Io4b3RJgdfK8bUITms/7xGYChXbI:2CvfGTaxX5+Lb/mSlITmOd+M
TLSH 4A7423C1DE2585248860B8F421B85CCD22EE551BAEC70E8DCB89A23DBDBC15EE57F750
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: tomtech.hu
Sending IP: 185.112.156.244
From: Annett Scholz| VENDITA <annett.scholz@diapath.com>
Subject: I: Ordine N. OR-0610
Attachment: Ordine N. OR-0610.pdf.gz (contains "Ordine N. OR-0610.pdf.exe")

Loki C2:
http://kovachevpress.com/other/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-10 11:37:05 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 3c80a7d1d549977570a966c905cf35fddec406dba4caebf2dd7782a06a2de30e

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments