MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 1245deb09158c69cf87370cca6bc0ab6251348b421f8561531cf382e224afd32. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 3
| SHA256 hash: | 1245deb09158c69cf87370cca6bc0ab6251348b421f8561531cf382e224afd32 |
|---|---|
| SHA3-384 hash: | 303cbd981195b06bbaae5d7ad0fcdccc24f47c7f0441338fe5d4d5b806d556a73f03f78ed36306630291cb491a1417a2 |
| SHA1 hash: | c061134454e43662e96524fa6386ae07950ddaaf |
| MD5 hash: | e65d2b508ae996b90042e26362a2b182 |
| humanhash: | oxygen-monkey-friend-freddie |
| File name: | LIST OF REAP MEMBERS NOMINATED FOR ELECTION.pdf.z |
| Download: | download sample |
| Signature | Loki |
| File size: | 137'201 bytes |
| First seen: | 2020-12-08 07:54:01 UTC |
| Last seen: | Never |
| File type: | z |
| MIME type: | application/x-rar |
| ssdeep | 3072:NsAjjkB2OuuPnAcIAaRyQxcP/Lm7rfGpjyRFtglZMiMj8Fi2J1VZ:Nxk2LMRIBysg/LPpjDnpM/iD |
| TLSH | 02D312502C7567CFF9FEC3E51C31A17295AA1A006741800EF6B077CA826D9F8CAE6E57 |
| Reporter | |
| Tags: | Loki z |
abuse_ch
Malspam distributing Loki:HELO: vhosts54.montevideo.net.uy
Sending IP: 200.40.79.224
From: REAP - Rice Exporters Association of pakistan <infor@reap.com.pk>
Subject: NOTIFICATION OF LIST OF REAP MEMBERS NOMINATED FOR ELECTION.
Attachment: LIST OF REAP MEMBERS NOMINATED FOR ELECTION.pdf.z (contains "LIST OF REAP MEMBERS NOMINATED FOR ELECTION.pdf.exe")
Loki C2:
http://51.195.53.27/~dasdas/ff.php
Intelligence
File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-12-08 07:54:11 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Loki
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.