MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 429e47c34d2bac699b1209881e4e25fc4d83a72ef783ac54a20df826f8ece469. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 429e47c34d2bac699b1209881e4e25fc4d83a72ef783ac54a20df826f8ece469
SHA3-384 hash: 8f423cd6902f1436351b1a95888f28a38c280adde4e55d8418d10ab07419fde4219161e66abd618ca24e990a21187acd
SHA1 hash: d7d5d493b7cc2ffdd73cd81901908875e187424d
MD5 hash: 1aacbb0ccbe9041195ea19c245d17c13
humanhash: xray-maine-snake-uranus
File name:DHL WAYBILLDOC 83737262.rar
Download: download sample
Signature Loki
File size:561'977 bytes
First seen:2020-10-21 08:48:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:4mWoDIDxYb0YqQPMfJ0uMroQLFlVsI9B0Oe/pdy1raO/VqtyXM1EBNm8oV5v4Atd:VLm2bUjEOgCTry1H/V9Xasg4Atd
TLSH A0C4232EC5B68BB409E355196CFFEE4080460471D02325229D96FF9C7A7E3B990B0B9F
Reporter abuse_ch
Tags:DHL Loki rar


Avatar
abuse_ch
Malspam distributing Loki:

HELO: server.filmworld.tv
Sending IP: 70.32.31.17
From: DHL Express <dhlSender@dhl.com>
Reply-To: DHL Express <dhlSender@dhl.com>
Subject: DHL Express Shipment Confirmation
Attachment: DHL WAYBILLDOC 83737262.rar (contains "DHL WAYBILLDOC 83737262.exe")

Loki C2:
http://195.69.140.147/.op/cr.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-21 08:19:12 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

rar 429e47c34d2bac699b1209881e4e25fc4d83a72ef783ac54a20df826f8ece469

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments