MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef57d009e03caead7f533951a4c6dddde151b6f1326b28f655dbee2bcb3fb697. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ef57d009e03caead7f533951a4c6dddde151b6f1326b28f655dbee2bcb3fb697
SHA3-384 hash: 6f1c00a875fe202706717c4d5caf00422a2fcbb35793aab6f6776df978ee5b4094a3de78259ffda422f209401803fcb0
SHA1 hash: 84620b09c1c691c9e5c12ad7a4da128e4923bd5e
MD5 hash: d6910c907d8191488757a66e4188aa9c
humanhash: sad-chicken-kentucky-north
File name:SCB Payment advice _pdf.gz
Download: download sample
Signature Loki
File size:390'582 bytes
First seen:2020-07-21 06:43:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:t5gHZtWFsisTSd7mjsVHK8lulzNxd6Rgc1RXqYbMFRxlndxQEejjp5Qgc:g6rsTeNJlulzNxcgc1pqYbMFRvnYEeHm
TLSH 60842355CEC59EA8C85CA84B3031DF254DE8135C0EA68BEA350F5086867FAEF50F879D
Reporter abuse_ch
Tags:gz Loki SCB


Avatar
abuse_ch
Malspam distributing Loki:

HELO: scb.com
Sending IP: 103.99.1.147
From: Standard Chartered Bank <noreply@scb.com>
Subject: Payment Advice from Standard Chartered Bank
Attachment: SCB Payment advice _pdf.gz (contains "file-00011444_pdf.exe")

Loki C2:
http://brokenskull.ga/Colba4/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-21 01:03:56 UTC
AV detection:
23 of 28 (82.14%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip ef57d009e03caead7f533951a4c6dddde151b6f1326b28f655dbee2bcb3fb697

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments