MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc596abf26c86b1ce8b434b4bc80bf0d76751783373f27db930011713c966255. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fc596abf26c86b1ce8b434b4bc80bf0d76751783373f27db930011713c966255
SHA3-384 hash: 916282a05434322b17087df126187051ad2ccadb9c4ac48d7ac6980321882de21863394f4ad51604f5bcace61772d885
SHA1 hash: 9fce70019023e4fea3b0540b8fc25965593fd3c1
MD5 hash: d081821d40ab4137a5f8f13f94640ec7
humanhash: utah-gee-india-jupiter
File name:PIEDĀVĀJUMA PIEPRASĪJUMS 29-06-2020·pdf.zip
Download: download sample
Signature Loki
File size:350'012 bytes
First seen:2020-06-29 12:37:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Wsdiv0CANnxhAUj00DzciR7KxdRvwkP4MzyY/fWCuhAJXMzggYsKNkzhPnahqFMC:Wsd74UDww6dRIc4u/fBXCga1tahJAT
TLSH 3B7423041B5FD2F7716F6970939F6E7AAF583A5FC6A5318861E31E3DE87CE600A011A0
Reporter abuse_ch
Tags:geo Loki LVA zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail.genoxy.tk
Sending IP: 103.109.37.216
From: Latvijas Universitāte <admin@lu.lv>
Subject: PIEDĀVĀJUMA PIEPRASĪJUMS (Latvijas Universitāte) EUI894/BU4600
Attachment: PIEDĀVĀJUMA PIEPRASĪJUMS 29-06-2020·pdf.zip (contains "PIEDĀVĀJUMA PIEPRASĪJUMS 29-06-2020·pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.PonyStealer
Status:
Malicious
First seen:
2020-06-29 12:39:11 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip fc596abf26c86b1ce8b434b4bc80bf0d76751783373f27db930011713c966255

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments