MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 235678afae67a874474bba158f96246ef5ca70292521e2b22b789021398cb3e6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | 235678afae67a874474bba158f96246ef5ca70292521e2b22b789021398cb3e6 |
|---|---|
| SHA3-384 hash: | 8e7eec01f78da263073b81fb76d9f4cafd369064356f183e7063cecc6da44c513431c1bc073dfe900e808b0439808a74 |
| SHA1 hash: | d40a8f22e2c4e616eb99cd4d49cad4f61e060142 |
| MD5 hash: | 0f58e05fb244673c1f0c10f556f0bc0b |
| humanhash: | quiet-virginia-delta-alanine |
| File name: | ETD 15-09-2020 (MV.HYUNDAI SUPREME V. 102N_PDF.gz |
| Download: | download sample |
| Signature | Loki |
| File size: | 427'467 bytes |
| First seen: | 2020-10-02 04:53:10 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 12288:kyu5RCaq3A+8E6rGzOm0V6HDyHEX1JzzBbYpz6:Fu5RCfw5rN2+EbzVspO |
| TLSH | 5F9423815DAD3D9D911367360CB2BB216C7FC12986866B6F1377A033B80806A0DE677F |
| Reporter | |
| Tags: | gz Loki |
cocaman
Malicious email (T1566.001)From: ""PT. YAMATO INDONESIA FORWARDING" <Ocean.import1@yamato.co.id>"
Received: "from server.veneta.com (unknown [180.235.150.169]) "
Date: "Fri, 02 Oct 2020 10:01:52 +0700"
Subject: "RE: ADJUSTMENT // PRE ALERT AT INDONESIA "NYK FUJI V.084S" LCL TO
JKT YGLNGO004466 // YIF-FW-19004159/"
Attachment: "ETD 15-09-2020 (MV.HYUNDAI SUPREME V. 102N_PDF.gz"
Intelligence
File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-02 04:55:06 UTC
File Type:
Binary (Archive)
Extracted files:
40
AV detection:
8 of 48 (16.67%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Lokibot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Dropping
Loki
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.