MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2fd6a1bef0310d30f48d979862970a81385dc4680054c71ffdc334fb68ef3357. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2fd6a1bef0310d30f48d979862970a81385dc4680054c71ffdc334fb68ef3357
SHA3-384 hash: d43ce45768daaab125f8577b28c3929f7352207c1446c9434e6b2dca4676c77e10847119d2bc811ad9c38979386853ca
SHA1 hash: f68add7167485dd447f99c296d341d9503fe6752
MD5 hash: f322614cddf22a3bda4f1c8ba1b81959
humanhash: bravo-arizona-finch-batman
File name:scan file-03811_pdf.gz
Download: download sample
Signature Loki
File size:433'204 bytes
First seen:2020-10-22 06:52:44 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:zD4ITqGtmMwLRKGYiKnyQ5LJTZ4tb7OJ7u0t:z8vZrLRKxf5ZZgoi0t
TLSH 35942386503D8934889F012B217FC519FC979314FF3B34F94B1728A576284AB6357ADE
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: hosted-by.rootlayer.net
Sending IP: 185.222.57.164
From: Dongguan Shuobao Industrial Equipment<jessie@shuobaocn.com>
Subject: RE: PROFORMA INVOICE (P.I) FOR CONFIRM
Attachment: scan file-03811_pdf.gz (contains "scan file-03811_pdf.exe")

Loki C2:
http://pabloservices.ga/Colba1/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-22 01:54:43 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 2fd6a1bef0310d30f48d979862970a81385dc4680054c71ffdc334fb68ef3357

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments