MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75e1fbe0b14e28882e197d2d8c9c9935fec96bdf102a97ba30e6b350a502c443. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 75e1fbe0b14e28882e197d2d8c9c9935fec96bdf102a97ba30e6b350a502c443
SHA3-384 hash: 936cad30e5ec8fde8434bbdf71f05fe79fb955a0ebe636d02904caf8cea12216514581e93dc1fff80a3c197942960022
SHA1 hash: ad95c204caf91f79c46c16d18f6f87a222c25e7c
MD5 hash: 84b94272311aa057b55a6a73890ec62f
humanhash: spaghetti-tennessee-mountain-beryllium
File name:Tax for this tax period is -702.23 AED.gz
Download: download sample
Signature Loki
File size:962'246 bytes
First seen:2021-02-11 10:06:36 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 24576:JsfEQE3fIk20C2KN38zqUhCZ/9ocF0jE3xj0:CfEQYfB1e3pvp0jEhj0
TLSH F72533955CAED3520160E8A7263D5B092C8DBC2D9E6DE1114CE4119D83ACF5BEFF22CB
Reporter abuse_ch
Tags:ARE geo gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: tax.gov.ae
Sending IP: 45.137.22.41
From: fta-reg <fta-reg@tax.gov.ae>
Subject: VAT Return Submission (refund position)
Attachment: Tax for this tax period is -702.23 AED.gz (contains "Tax for this tax period is -702.23 AED.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
ByteCode-MSIL.Trojan.Tnega
Status:
Malicious
First seen:
2021-02-12 04:16:41 UTC
AV detection:
15 of 47 (31.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

gz 75e1fbe0b14e28882e197d2d8c9c9935fec96bdf102a97ba30e6b350a502c443

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments