MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9235243d6dca0bb2bdad8abc90ebb549d4e08a0e2a9b73298d879866b0cb717e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 9235243d6dca0bb2bdad8abc90ebb549d4e08a0e2a9b73298d879866b0cb717e
SHA3-384 hash: 958b4c8feed8b23a29a306492ea67cb211896327af51c5f8e4e47924a07b740c721ed2a1019e698b629c8c1f8675fb97
SHA1 hash: 138765c0c2e1306e55bd6c1808cb8a1fa87f2932
MD5 hash: 95c7020eec777396a224712e7d96aa99
humanhash: nuts-october-hawaii-magnesium
File name:Company Profile.zip
Download: download sample
Signature Loki
File size:408'083 bytes
First seen:2020-08-17 19:13:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:lp9QidXW9c9t+gq0ziwxp2B+3ZUyjcvgj+WJbKO:lp9QZUt+MiI2B+3Z7Kgj+pO
TLSH F29423719F835E2EF01701AB14ECFE430670624B55A5B3704229DC939A7BC62E7B2776
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.sgbcg.com
Sending IP: 113.11.251.241
From: farzna@webmasterstech.com
Subject: Retail Inquiry (Wholesale & Retail)
Attachment: Company Profile.zip (contains "Company Profile.exe")

Loki C2:
http://eloquentcs.com/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-17 19:15:07 UTC
AV detection:
23 of 29 (79.31%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 9235243d6dca0bb2bdad8abc90ebb549d4e08a0e2a9b73298d879866b0cb717e

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments