MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 235678afae67a874474bba158f96246ef5ca70292521e2b22b789021398cb3e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 235678afae67a874474bba158f96246ef5ca70292521e2b22b789021398cb3e6
SHA3-384 hash: 8e7eec01f78da263073b81fb76d9f4cafd369064356f183e7063cecc6da44c513431c1bc073dfe900e808b0439808a74
SHA1 hash: d40a8f22e2c4e616eb99cd4d49cad4f61e060142
MD5 hash: 0f58e05fb244673c1f0c10f556f0bc0b
humanhash: quiet-virginia-delta-alanine
File name:ETD 15-09-2020 (MV.HYUNDAI SUPREME V. 102N_PDF.gz
Download: download sample
Signature Loki
File size:427'467 bytes
First seen:2020-10-02 04:53:10 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 12288:kyu5RCaq3A+8E6rGzOm0V6HDyHEX1JzzBbYpz6:Fu5RCfw5rN2+EbzVspO
TLSH 5F9423815DAD3D9D911367360CB2BB216C7FC12986866B6F1377A033B80806A0DE677F
Reporter cocaman
Tags:gz Loki


Avatar
cocaman
Malicious email (T1566.001)
From: ""PT. YAMATO INDONESIA FORWARDING" <Ocean.import1@yamato.co.id>"
Received: "from server.veneta.com (unknown [180.235.150.169]) "
Date: "Fri, 02 Oct 2020 10:01:52 +0700"
Subject: "RE: ADJUSTMENT // PRE ALERT AT INDONESIA "NYK FUJI V.084S" LCL TO
JKT YGLNGO004466 // YIF-FW-19004159/"
Attachment: "ETD 15-09-2020 (MV.HYUNDAI SUPREME V. 102N_PDF.gz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-02 04:55:06 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 235678afae67a874474bba158f96246ef5ca70292521e2b22b789021398cb3e6

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
Loki

Comments