MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a1805061f870369f91372d5f919adf9782c2effaa8ea233bed2e80532c01ebb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6a1805061f870369f91372d5f919adf9782c2effaa8ea233bed2e80532c01ebb
SHA3-384 hash: c77330c0523cdceec1839361b549a28eaa859f1b7d29b0273ed438966c074da9399a6a87df79a99410777d360c620b89
SHA1 hash: ec643eb983325b8548933d39832a3d08cc56841c
MD5 hash: 8648fc07685776dc8dff053e027629fd
humanhash: march-wolfram-december-summer
File name:TNT Numero.gz
Download: download sample
Signature Loki
File size:412'209 bytes
First seen:2020-11-18 12:10:47 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 6144:gbBFrf9z3PW+EssktEJMrt7l8gFYkx6AiERhI3ygNkmQlzKzEcUL:QrVhEhktEJMrtxdvxfg6Ubc
TLSH 0D94237EB7D290045749E976378CB7303153A35B9C4C84491A4DE3B9C1EA9990F2F2CD
Reporter abuse_ch
Tags:geo gz ITA Loki TNT


Avatar
abuse_ch
Malspam distributing Loki:

From: TNT EXPRESS <dani.hilman@barata.com>
Subject: Notifica di fatturazione elettronica TNT Numero di spedizione: 0468356440 - URGENTE
Attachment: TNT Numero.gz (contains "TNT Numero.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-11-18 11:40:47 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 6a1805061f870369f91372d5f919adf9782c2effaa8ea233bed2e80532c01ebb

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments