MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c82e5cdf35057cf4ff0c2209f0fe7f234893db8c3cf78f0a77646e3b29dff435. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c82e5cdf35057cf4ff0c2209f0fe7f234893db8c3cf78f0a77646e3b29dff435
SHA3-384 hash: 9e72e6b550adf03e9dd6c7136b2c41abe54f63b23ce4f80f3d5154843ab8557bb49094d33346460fec8795674875acbb
SHA1 hash: 38bd143597877538ae25bac4b8b72e6cc263733d
MD5 hash: 865c3847a01471ba9e3abb69bf1c1c6c
humanhash: texas-mike-seven-kilo
File name:SKR-JONATHAN SWIFT 0QA5CN.pdf.gz
Download: download sample
Signature Loki
File size:204'617 bytes
First seen:2020-07-03 06:16:49 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:2zRlNVH/TzMbnUhwX0Y4ExYE6clVxyRto0bFKyc:2zRlN9/HMbnOwkY4ExYENlVqto0S
TLSH D414239F1580A3D1477D86DB0172BB72462025CF89FB625B57671096B44CC2B1CAFA3E
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: cpanel3.centrin.net.id
Sending IP: 202.146.241.47
From: CMA CGM JKT || PARTOGI Johannes <amelia@sinokor.co.id>
Subject: RE: AASW010244 PT CHIH HORNG METAL & ELECTRIC INDUSTRY
Attachment: SKR-JONATHAN SWIFT 0QA5CN.pdf.gz (contains "SKR-JONATHAN SWIFT 0QA5CN.pdf.exe")

Loki C2:
http://niskioglasi.rs/test1/Panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-03 06:18:08 UTC
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz c82e5cdf35057cf4ff0c2209f0fe7f234893db8c3cf78f0a77646e3b29dff435

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments