MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ce3a5fa559b80bf4a696e22675ddeb95a7fda9d0747d7b2a412bbe1c56789c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1ce3a5fa559b80bf4a696e22675ddeb95a7fda9d0747d7b2a412bbe1c56789c5
SHA3-384 hash: 5fee510be5881af698ea40f13fbf8451f9b872b3aa47ced87a2a10d9745b9e0264468684bbe246c12abc83f3ba2ab10a
SHA1 hash: dbc47f1468667b84f6abedb480ee887c9bda670c
MD5 hash: 97e8646ceabe72bfed0ca7d5dc7d82d9
humanhash: fruit-delta-five-alanine
File name:New order_0012021PDF.rar
Download: download sample
Signature Loki
File size:548'532 bytes
First seen:2021-01-14 19:04:59 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:eYcoYuRmilEk65PnwKJCCN8CAy83pRECJYYEXEedjqu59:e3C7Sk65oK4alCmxBP9
TLSH ABC4233E2571111EDB7BA767B88D23140CF9F93721479C206FBDBE6576C2888EC86491
Reporter abuse_ch
Tags:Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: vps.doctorpc.pe
Sending IP: 198.38.91.247
From: Purchase@kancelaria-tw.pl
Reply-To: apaccustomerrservices10@gmail.com
Subject: Nuevo orden_0012021
Attachment: New order_0012021PDF.rar (contains "wXcOIcc1XOk46Uh.exe")

Loki C2:
http://lightloog.ddns.net/log/panel/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-14 19:05:06 UTC
AV detection:
7 of 46 (15.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 1ce3a5fa559b80bf4a696e22675ddeb95a7fda9d0747d7b2a412bbe1c56789c5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments