MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 25bfe953313ef97dfaac9f6f624a2b09d1f98df76f103c62f65169efa6d532b0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ModiLoader
Vendor detections: 4
| SHA256 hash: | 25bfe953313ef97dfaac9f6f624a2b09d1f98df76f103c62f65169efa6d532b0 |
|---|---|
| SHA3-384 hash: | 904e919dee39f2a3f3202c673f86fed3c8e0b87c6eedff6bb04b30d1b66a7cccef0f21299741b90a9b8f97c2b59f381e |
| SHA1 hash: | 360c40e4cf9118ef91a0242e9e297639ea40b423 |
| MD5 hash: | 742ba13cf123914fcf79ada1ac2eb7c7 |
| humanhash: | papa-paris-kitten-spaghetti |
| File name: | wire transfer notification advice.rar |
| Download: | download sample |
| Signature | ModiLoader |
| File size: | 499'034 bytes |
| First seen: | 2020-10-27 12:48:20 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 12288:CvgEDMdcmIXVxqECfg2slSRCgvva+g71cNC7PmGeBqgE3D5vJo7TKMY/m:CHPbV4E+g2s4RX3ru1c6eGeBqvyHAe |
| TLSH | E5B423460924746DB53BE544E8BAF4FCF9FE9328101A5E1FCEE50E8B626B9016C7C4C1 |
| Reporter | |
| Tags: | HSBC ModiLoader rar |
abuse_ch
Malspam distributing ModiLoader:HELO: post2-gw.beenets.com
Sending IP: 119.63.80.28
From: HSBC Bank plc <zofia.sitnik@hsbc.com>
Subject: Advice refund from HSBC
Attachment: wire transfer notification advice.rar (contains "wire transfer notification advice.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Ymacco
Status:
Malicious
First seen:
2020-10-27 10:12:26 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
ModiLoader
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.