MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 deb3ad33569c0084e7120168e9ed2d8d569741b54103f20f11d0dc33df160954. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: deb3ad33569c0084e7120168e9ed2d8d569741b54103f20f11d0dc33df160954
SHA3-384 hash: 59fc4efcdae185075dcfc455caa66dd2774e89b6be545f542220efa4bf8b17b8da29be75110891c3b78034097ebfb483
SHA1 hash: ce0569f19f3bb6d3611cb58fdc32c200d39d88f6
MD5 hash: fe08413ad03aa312c5594b2a9fd3707f
humanhash: rugby-east-mike-robert
File name:Purchase Order 060920A.zip
Download: download sample
Signature Loki
File size:374'983 bytes
First seen:2020-06-23 05:31:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:lGevJ2mrRGlU0AZb1x2uR0oGCvJB9vALk+l7Sz8FlOKqypEkKBF3c29uz8m:wM2mrRCU0in2UMo/+LkeGGIXvG29uv
TLSH ED8423246A2975FB105727D54FD7E4B7FC5931B4C88A106686A24E63FFF1E043E06B24
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: gmail.com
Sending IP: 156.96.62.70
From: Ben Faiella <Faielladwalklate@gmail.com>
Reply-To: hectorgreg99@gmail.com
Subject: Purchase Order 060920A
Attachment: Purchase Order 060920A.zip (contains "Purchase Order 060920A.exe")

Loki C2:
http://koreanbeautyexpert.com/guii/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-23 05:33:06 UTC
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip deb3ad33569c0084e7120168e9ed2d8d569741b54103f20f11d0dc33df160954

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments