MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66c302a907e73546d7a24cb96068a686837bb8e2a6652932643fa493dedce4f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66c302a907e73546d7a24cb96068a686837bb8e2a6652932643fa493dedce4f0
SHA3-384 hash: 44cb5daa30349cbedf49440bd40cf5e4d56b2a8d28f6cb26704bb7a15317b62119c33aa39f29cef8d668e633004e3ddf
SHA1 hash: d16e92d4358320d6b82989e1cbea0536d06625bd
MD5 hash: 003908efbb374f981e1e5e1a9b061804
humanhash: nitrogen-oscar-lion-lion
File name:Shipment2068629 BC-pdf.gz
Download: download sample
Signature Loki
File size:387'955 bytes
First seen:2020-06-26 08:22:26 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:a2624guiyJDOzjeedwFIwv9djzz8j1wgQTj5K05ULLK1UJ7MQBnKwt0ndjE09i53:aGyJOGedHQjzziaY05ULLGUJA06tE0Ql
TLSH 968423ADE34134FF061167FB2F95AB0441C8FE0B14608888EBB7EC7D5769219EB76291
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: maleo.empatdns.com
Sending IP: 180.235.151.11
From: ROUND THE WORLD LOGISTICS CORP (M) SDN BHD <import.fli@flicargo.com>
Subject: RE: [EXT] RE: CIPL and Shipment Photos: - 2068629 - FCA, by SEA
Attachment: Shipment2068629 BC-pdf.gz (contains "gunzipped")

Loki C2:
http://airmanselectiontest.com/dest/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-26 08:24:05 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 66c302a907e73546d7a24cb96068a686837bb8e2a6652932643fa493dedce4f0

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments