MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4709414d75a7f85b38e8b2ec460b18d60bf636f3132eb6e8e74dfbb6ee1bb746. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4709414d75a7f85b38e8b2ec460b18d60bf636f3132eb6e8e74dfbb6ee1bb746
SHA3-384 hash: 0eb7ac1a00db8edd0fd0a696aaa5969b4a7c51903036d31bc8ef617e0b774ae58e1129bd9f464bb33738494aad64065c
SHA1 hash: 7c157909dfebbb51865c1c58a84c1d4a2846e2f6
MD5 hash: c588977328fa853b4d58352506f92a3d
humanhash: diet-august-hawaii-twenty
File name:Inv_22620_scan.gz
Download: download sample
Signature Loki
File size:375'454 bytes
First seen:2020-06-23 06:54:35 UTC
Last seen:2020-06-23 09:05:38 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:f+qcTQWshhx3QWCZzuNtUD+4T9OU7HYCn6yj+oT+D2GJl4zdnij:f+qcVshhxAdtP9l7X66+PDlLsnY
TLSH DB84237D1F127D93C04D7DEA185FE52AA40A7B858AE10DC6B6A5EB3AAC03D0CD4578CC
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: sevegep.com.cy
Sending IP: 103.207.38.18
From: Petros Malaktos <petros@sevegep.com.cy>
Subject: RE: ATTACHED INVOICE WITH PAYMENT SWIFT
Attachment: Inv_22620_scan.gz (contains "scan007.exe")

Loki C2:
http://superson-com.cf/L7/fre.php

Intelligence


File Origin
# of uploads :
3
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-23 06:56:04 UTC
File Type:
Binary (Archive)
Extracted files:
294
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 4709414d75a7f85b38e8b2ec460b18d60bf636f3132eb6e8e74dfbb6ee1bb746

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments