MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0b164ce7274b2912a6ba79644466e57659f9931aae63085b06af0ac9933064b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 0b164ce7274b2912a6ba79644466e57659f9931aae63085b06af0ac9933064b1 |
|---|---|
| SHA3-384 hash: | b7666cff6cbfb500751eef387ad11b2b325bad480f732dd2dc2365989a7a0b74b5a919d870d9c0805064386b9f3f8bf8 |
| SHA1 hash: | 83dcb2cda7f4df531d09510d7b2dfcce923b77c2 |
| MD5 hash: | 43654458ac517bd0b81d89948a5a6863 |
| humanhash: | triple-pizza-quiet-burger |
| File name: | PERMINTAAN PENAWARAN 06-08-2020·pdf.zip |
| Download: | download sample |
| Signature | Loki |
| File size: | 415'560 bytes |
| First seen: | 2020-08-06 05:51:02 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 12288:yolHNUxrhYKSrhuwXy+dGZJeBrow33eoCDY:IxrmxhpjddBx33eY |
| TLSH | E79423AD884F3FF1B11CCCAB32E99465D416CFD7A30A59F8E33545362DA173686E2920 |
| Reporter | |
| Tags: | Loki zip |
abuse_ch
Malspam distributing Loki:HELO: mail.genogan.cf
Sending IP: 45.147.162.118
From: UNIVERSITAS GADJAH MADA <admin@ugm.ac.id>
Subject: PERMINTAAN PENAWARAN (UNIVERSITAS GADJAH MADA) ASI894/ID400
Attachment: PERMINTAAN PENAWARAN 06-08-2020·pdf.zip (contains "PERMINTAAN PENAWARAN 06-08-2020·pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-08-06 05:52:12 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Tinba
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.