MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53a23ee98bf2e4f7808c675b6a98cecfd7cf689dd1ca3ce194d431ad10f5dd68. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 53a23ee98bf2e4f7808c675b6a98cecfd7cf689dd1ca3ce194d431ad10f5dd68
SHA3-384 hash: 8fd41e18be9d3e2695ab2abad67046f63e9609b7b1dc9a6090d5cf38beb9910ae44ea672146e86a30cbf76797a390643
SHA1 hash: e3a0dbe0bedd3a32c0928988be1a362fe8c20bc5
MD5 hash: 15055acf662984806bf64004a2fb55ad
humanhash: four-seventeen-comet-mirror
File name:rfq3076h.pdf.zip
Download: download sample
Signature Loki
File size:265'748 bytes
First seen:2020-06-10 11:58:30 UTC
Last seen:2020-06-10 15:28:01 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:Z4aN0b2uXfgqF1LqgZ0lw4vrbAauDqgsa66rcaPa6gj1ah:2hIq7Hqlw4vrboUFM
TLSH 944423C33B1E8FCD8A78C551D8CD8DD570D2BAC6AC209D2F168D90791C58F93E56AA0E
Reporter abuse_ch
Tags:Loki zip


Avatar
abuse_ch
Malspam distributing Loki:

HELO: corneillesima.com
Sending IP: 156.96.47.116
From: Goran skimic<advertising@corneillesima.com>
Reply-To: Goran skimic<adveitising@corneillesima.com>
Subject: revised product enquiry june rfq3076h
Attachment: rfq3076h.pdf.zip (contains "rfq3076h.pdf.exe")

Loki C2:
http://irangoodshop.com/nop/fre.php

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-10 12:00:07 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 53a23ee98bf2e4f7808c675b6a98cecfd7cf689dd1ca3ce194d431ad10f5dd68

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments