MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f155423b751ca96562ad58ebce32951717f061d6a10b5ba6f3783ecf700ccca2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f155423b751ca96562ad58ebce32951717f061d6a10b5ba6f3783ecf700ccca2
SHA3-384 hash: c58e1705161877a3658795dfdbb1a6e81b54af3c1c5868a662b18f3d7e3a921d28efec4cd8ed4fb3be34ace95afc19ca
SHA1 hash: c694959315b02a92f3d64bf52b167fdbfc27166c
MD5 hash: 381a8ae8b05fb635142cd53cc2cc728c
humanhash: leopard-alanine-april-item
File name:DOC Z34253608.cab
Download: download sample
Signature Loki
File size:576'165 bytes
First seen:2020-10-27 10:20:04 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 12288:6SEQlEVCBioqvmuoOuldpbqGtGZGc/wHp9m9oJCAaF5Au5Eok:6+lEYjqvmiub2/YTAokV5Rlk
TLSH F9C423EFEE9A647E955D531A7261A4AF719548D603C0402886CFEBCAD5D0C3FEF0A843
Reporter abuse_ch
Tags:cab Loki


Avatar
abuse_ch
Malspam distributing Loki:

HELO: xmx0.517.awnex.ml
Sending IP: 46.101.17.68
From: y-kamiariya <y-kamiariya@fmarine.co.jp>
Reply-To: ops@fmarine.co.jp
Subject: RE: MV. KEY FRONTIER (ETA: KAW THAUNG : 05-11-2020) ESTD PORT D/A
Attachment: DOC Z34253608.cab (contains "DOC Z34253608.exe")

Loki C2:
http://ytho.com.vn/.ythocom/need/work/Panel/five/fre.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-27 05:15:41 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

cab f155423b751ca96562ad58ebce32951717f061d6a10b5ba6f3783ecf700ccca2

(this sample)

  
Dropping
Loki
  
Delivery method
Distributed via e-mail attachment

Comments