MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6ac4051e1a48bec6efdc6d95dffafc054af5d526151a7932edd9a9f608df1e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d6ac4051e1a48bec6efdc6d95dffafc054af5d526151a7932edd9a9f608df1e0
SHA3-384 hash: 4dd9c7d3b63fef284dae0251c6ca50e92dc2535c9be33a56cf5c1b46a8f5b2c77503f49ace9f8be57eeacfe40651c96b
SHA1 hash: 0171219098cde6a99835d8772cfefbc27b1aa206
MD5 hash: 5707a8f77349d4b8591e74cef596da48
humanhash: floor-failed-virginia-artist
File name:scan-12-08-2020-New_PO IMG-Updated.r00
Download: download sample
Signature ModiLoader
File size:416'055 bytes
First seen:2020-08-13 11:10:41 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 6144:JTRHi35uEM+l5eFvEhJ5yRB3Mrk24lUkOz6ZsU13yjVGLbWyVskxmlY+P:JTRQRMOMg02k99Oz6ZJ13yyjRUSi
TLSH 7A9423B1B25B8918C2EF13E4CE7BF866A8BC985FF3FB7DD341502860512560416AD9BC
Reporter abuse_ch
Tags:ModiLoader r00


Avatar
abuse_ch
Malspam distributing ModiLoader:

From: "Chandru Rajesh Amith " <chandru@pol-group.com>
Subject: RV: Request for quote . Update Order
Attachment: scan-12-08-2020-New_PO IMG-Updated.r00 (contains "scan-12-08-2020-New_PO IMG-Updated.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Delf
Status:
Malicious
First seen:
2020-08-13 07:09:46 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

r00 d6ac4051e1a48bec6efdc6d95dffafc054af5d526151a7932edd9a9f608df1e0

(this sample)

  
Dropping
ModiLoader
  
Delivery method
Distributed via e-mail attachment

Comments