MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a9ecaef28fa2b66e9c0471affeb1a6442d53c97987ac49a684233c4806f6bd5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4a9ecaef28fa2b66e9c0471affeb1a6442d53c97987ac49a684233c4806f6bd5
SHA3-384 hash: 0fb6ae53ad56860cc9447fbf3b729d830323f945df2f49e381ad9c8c99b807109e86224d8d526b1ca727a46e1a3bb217
SHA1 hash: 4b1de9ca4e4640085c5c7866bfa12406f51b3025
MD5 hash: c8353f3c34e1569d8752d71a7fd4577f
humanhash: jupiter-california-magnesium-mirror
File name:Shipment Details.gz
Download: download sample
Signature Loki
File size:492'473 bytes
First seen:2020-10-16 10:49:29 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:TqvLH6eUkQDTV8xNXjm+gaEstK3urX+n+yrD33Wo5mzAY1zrzf/MQRWYK4VvEb15:fexQmxljm7XsEaUXX33Cz37k1p2Ru
TLSH AEA423D9BDE0385864382F4B3F2B91428934A02E44B1D7591A75CF637E417E2EBEEE11
Reporter abuse_ch
Tags:gz Loki TNT


Avatar
abuse_ch
Malspam distributing Loki:

From: "TNT EXPRESS" <noreply@520.cxino.ml>
Subject: TNT Consignment Notification for 7048397463
Attachment: Shipment Details.gz (contains "Shipment Details.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-10-16 05:37:20 UTC
AV detection:
16 of 27 (59.26%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 4a9ecaef28fa2b66e9c0471affeb1a6442d53c97987ac49a684233c4806f6bd5

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments