MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f281eb528655f3faa459c8f21be8dc1c6ff4cfee78d81f5c82edb75799a293c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Loki


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: f281eb528655f3faa459c8f21be8dc1c6ff4cfee78d81f5c82edb75799a293c0
SHA3-384 hash: 917f7f5975185fd5448213d228e1e172209e9a0272f91a93465d0788b767093ad2beba520dbea4d29c1c3aa39d5d4e55
SHA1 hash: a2dda0cc6facb5960bf30f1336967f120774cb0b
MD5 hash: 42ffe9b8d756a8c02e38f0e0e7948f5d
humanhash: bacon-white-happy-uniform
File name:SF Express New Order_INV 2019022411_gpj.zip
Download: download sample
Signature Loki
File size:348'374 bytes
First seen:2021-01-12 17:59:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:Q087ku9savFShjcpenSzIPMZotU4jfwrSN+WpXoMJVjgNRvOkA6zdAZi:/8YLavQapenS80StNjxpXoMJVjgNhe63
TLSH 737423E7EB53C1E52DE49125CFE7C9A6C0C07F4538B4448E43811448AB5AEBFD8A8E9D
Reporter abuse_ch
Tags:zip


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: vm1BA2474
Sending IP: 217.76.158.168
From: SF Express <jeffie.lee@assudamal.com >
Subject: SF Express New Order_INV 2019022411
Attachment: SF Express New Order_INV 2019022411_gpj.zip (contains "IMG_73344332‮gpj.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-12 17:51:00 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Loki

zip f281eb528655f3faa459c8f21be8dc1c6ff4cfee78d81f5c82edb75799a293c0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments