MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ca85dd760ced371a83420498d1782eb41176a065099d9ba3e5b33deb03c42b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0ca85dd760ced371a83420498d1782eb41176a065099d9ba3e5b33deb03c42b0
SHA3-384 hash: d24e7d526894794ce5fe927f7bb8bbbb13aeec99d2fd4d94b3b75356249fd00c6040b1460d3cff2e1c47064e6a0328e6
SHA1 hash: 971229a85ac94b57c2b4c561ce974245193c7774
MD5 hash: 8852fa042a19b570db5c56cec6a56267
humanhash: carpet-apart-mockingbird-winner
File name:CV_SrinivasaBabuAdhikari.pdf.gz
Download: download sample
Signature Loki
File size:145'904 bytes
First seen:2021-01-11 08:16:42 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 3072:XNjoj7acDC2vS/1BWy4hXaH4IJgvXOEQQVxqIzGZrQsUloGc5:toj7agvg6bXkngvXOEQAxqVQs6e5
TLSH 47E3121CC0637ED6B18923D5064D7648C5723E6ABDBCF9F098E6C92BA3F0904E51A477
Reporter abuse_ch
Tags:gz Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail.gratiajm.co.id
Sending IP: 103.112.5.22
From: srinivasa_may@yahoo.com
Subject: RE: Job Application
Attachment: CV_SrinivasaBabuAdhikari.pdf.gz (contains "CV_SrinivasaBabuAdhikari.pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-11 01:39:29 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 0ca85dd760ced371a83420498d1782eb41176a065099d9ba3e5b33deb03c42b0

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments