MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f281eb528655f3faa459c8f21be8dc1c6ff4cfee78d81f5c82edb75799a293c0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Loki
Vendor detections: 4
| SHA256 hash: | f281eb528655f3faa459c8f21be8dc1c6ff4cfee78d81f5c82edb75799a293c0 |
|---|---|
| SHA3-384 hash: | 917f7f5975185fd5448213d228e1e172209e9a0272f91a93465d0788b767093ad2beba520dbea4d29c1c3aa39d5d4e55 |
| SHA1 hash: | a2dda0cc6facb5960bf30f1336967f120774cb0b |
| MD5 hash: | 42ffe9b8d756a8c02e38f0e0e7948f5d |
| humanhash: | bacon-white-happy-uniform |
| File name: | SF Express New Order_INV 2019022411_gpj.zip |
| Download: | download sample |
| Signature | Loki |
| File size: | 348'374 bytes |
| First seen: | 2021-01-12 17:59:13 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:Q087ku9savFShjcpenSzIPMZotU4jfwrSN+WpXoMJVjgNRvOkA6zdAZi:/8YLavQapenS80StNjxpXoMJVjgNhe63 |
| TLSH | 737423E7EB53C1E52DE49125CFE7C9A6C0C07F4538B4448E43811448AB5AEBFD8A8E9D |
| Reporter | |
| Tags: | zip |
abuse_ch
Malspam distributing unidentified malware:HELO: vm1BA2474
Sending IP: 217.76.158.168
From: SF Express <jeffie.lee@assudamal.com >
Subject: SF Express New Order_INV 2019022411
Attachment: SF Express New Order_INV 2019022411_gpj.zip (contains "IMG_73344332‮gpj.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
124
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-12 17:51:00 UTC
AV detection:
14 of 29 (48.28%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Kryptik
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.