MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1295f79d18d19e071c6381e55aafee07750793e67004cf01d0eb9e918ccae3f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1295f79d18d19e071c6381e55aafee07750793e67004cf01d0eb9e918ccae3f2
SHA3-384 hash: 083b687330afa4d6b9620f5a31f13b76bc5c375443deb80ef00432201c8f94814d125512801cec84d68908569ddc4d8d
SHA1 hash: f5566af49ac866608c76a9bf40edcac2e601ce76
MD5 hash: dde68b48c60909ec71707465217d2dfe
humanhash: rugby-april-rugby-india
File name:SDT_R224e18032356210_XLS.arj
Download: download sample
Signature Loki
File size:562'009 bytes
First seen:2020-10-21 09:53:15 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:7A0Aee2SV+kbJzSYEtvLM7AcJGY9Fv2lI1TXZkMQFCPPt:7ASM+szSYGTP49YKJksPt
TLSH 99C42344E3E6EBFC07D242635CC3C7B761DF2859B3618589279877B4AA72F88B42510E
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: revenant.kryonics.net
Sending IP: 186.177.99.38
From: cindy@shafichina.com
Subject: RE: Approved Proforma _ Grassco
Attachment: SDT_R224e18032356210_XLS.arj (contains "SDT_R224e18032356210_XLS.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-21 03:03:47 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip 1295f79d18d19e071c6381e55aafee07750793e67004cf01d0eb9e918ccae3f2

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments