MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25bfe953313ef97dfaac9f6f624a2b09d1f98df76f103c62f65169efa6d532b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 25bfe953313ef97dfaac9f6f624a2b09d1f98df76f103c62f65169efa6d532b0
SHA3-384 hash: 904e919dee39f2a3f3202c673f86fed3c8e0b87c6eedff6bb04b30d1b66a7cccef0f21299741b90a9b8f97c2b59f381e
SHA1 hash: 360c40e4cf9118ef91a0242e9e297639ea40b423
MD5 hash: 742ba13cf123914fcf79ada1ac2eb7c7
humanhash: papa-paris-kitten-spaghetti
File name:wire transfer notification advice.rar
Download: download sample
Signature ModiLoader
File size:499'034 bytes
First seen:2020-10-27 12:48:20 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:CvgEDMdcmIXVxqECfg2slSRCgvva+g71cNC7PmGeBqgE3D5vJo7TKMY/m:CHPbV4E+g2s4RX3ru1c6eGeBqvyHAe
TLSH E5B423460924746DB53BE544E8BAF4FCF9FE9328101A5E1FCEE50E8B626B9016C7C4C1
Reporter abuse_ch
Tags:HSBC ModiLoader rar


Avatar
abuse_ch
Malspam distributing ModiLoader:

HELO: post2-gw.beenets.com
Sending IP: 119.63.80.28
From: HSBC Bank plc <zofia.sitnik@hsbc.com>
Subject: Advice refund from HSBC
Attachment: wire transfer notification advice.rar (contains "wire transfer notification advice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-10-27 10:12:26 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

rar 25bfe953313ef97dfaac9f6f624a2b09d1f98df76f103c62f65169efa6d532b0

(this sample)

  
Dropping
ModiLoader
  
Delivery method
Distributed via e-mail attachment

Comments