MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 970f2cbe2ab76df4e1d8835ac7bf8315705e646ee52bc1eabc6df3c64ed5a93c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 970f2cbe2ab76df4e1d8835ac7bf8315705e646ee52bc1eabc6df3c64ed5a93c
SHA3-384 hash: 911be160c41c13d7ab16b3dbe20a701ad19614aa8aaa01eb05accca9bcc400e6edcc41fa6e7f8261a08f72f00388519c
SHA1 hash: c836e708cf5f08ae0158386782569ae5adc78791
MD5 hash: 2b97ec2c46fbe62056434765c1da0f01
humanhash: autumn-autumn-september-vegan
File name:PO_003777.arj
Download: download sample
Signature Loki
File size:351'262 bytes
First seen:2020-10-27 14:31:22 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 6144:C+NPy/k+7HQljNgEuzWLbOLihh6SsYY8RmeBzj5sKbJz3x/NUk+TfYtyBlv:CYYjkjeEutLihhcYY8nzj1h/Kk+ctEt
TLSH 9074233B30B6F5A1EFC97135860D0C6BD2B68554F84E592CD9EEA972DEB3465F0A2C00
Reporter abuse_ch
Tags:arj Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: mail.madalinagrup.ro
Sending IP: 89.120.113.36
From: Nouman Naseer <nouman@pioneersystem.org>
Subject: Re: purchase order
Attachment: PO_003777.arj (contains "PO_003777.exe")

Loki C2:
http://mecharnise.ir/eb2/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-27 12:51:39 UTC
AV detection:
6 of 48 (12.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

arj 970f2cbe2ab76df4e1d8835ac7bf8315705e646ee52bc1eabc6df3c64ed5a93c

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments