MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dae03e7693f1c2385c49f9857db98f88c9aea503ea4cbea13445e61cbc8794cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dae03e7693f1c2385c49f9857db98f88c9aea503ea4cbea13445e61cbc8794cb
SHA3-384 hash: 83a9461aebf688ef9fe2d5967b006a86f065b0b1f3e8ca39f40293d3b10ed8d969db6448f77a6ec4715a233370cc428c
SHA1 hash: 634a4a156c397e62e0bdf0807e952a975ca5d15f
MD5 hash: fd01e68dcd839bf3d9ecc34f96e40d85
humanhash: vegan-oxygen-leopard-violet
File name:kwitansi bank 0070620200012-pdf.gz
Download: download sample
Signature Loki
File size:222'898 bytes
First seen:2020-07-07 12:53:40 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:F0SPfZWUTrzWZo9CM0fHh0m5Bfa4vovvGf2Xd:GSPRWor6Zo9IfuGaumdXd
TLSH 222423008FCE7D3E81E3E24E52E6806DD398913092551197B19B7AEDD7C5262FB0B8E7
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: smtpgw2.nayatel.com
Sending IP: 115.186.188.155
From: Banco Patagonia <vdelapena@bancopatagonia.com.ar>
Subject: Patagonia e-bank Empresas: Aviso de transferencia de fondos
Attachment: kwitansi bank 0070620200012-pdf.gz (contains "kwitansi bank 0070620200012-pdf.exe")

Loki C2:
http://mygreencity.in/scripts/Panel/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-07 12:55:05 UTC
AV detection:
33 of 48 (68.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz dae03e7693f1c2385c49f9857db98f88c9aea503ea4cbea13445e61cbc8794cb

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments