MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3573eb2fa96610a18fcb5ae8157af66b5802aa268c66d022f358040c6079ba1b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 3573eb2fa96610a18fcb5ae8157af66b5802aa268c66d022f358040c6079ba1b
SHA3-384 hash: 89992ea70210c2c2914c9784673d8e1b065ae0b40880fe91c7ff236bd1ae85bd689703674ea9bf538f97ae9dce75212a
SHA1 hash: 671d0a367996f4e965fa49ed399209d2212abbde
MD5 hash: bdd5ddc25f4017dcdf218e0a59a311f9
humanhash: yankee-alpha-solar-bulldog
File name:OKaxjorl_Kawthar.img
Download: download sample
Signature ModiLoader
File size:1'835'008 bytes
First seen:2020-10-12 14:48:52 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:eHyUt7yQaaPXmlUM4aSHTUn1PQeLNzV2H1Q/:eH5tZaaPmljNogV2
TLSH 8685E0E3B2E248B3C16666754C4BC7BD5829BE132D24A9463AFD3D4C3F7A6803927153
Reporter abuse_ch
Tags:img ModiLoader


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: host8.axxesslocal.co.za
Sending IP: 154.0.175.45
From: Kawthar Services & Total Industrial Supplies <info@kawthar.net>
Subject: Kawthar Services & Total Industrial Supplies- Order ID: OKAXJORI/10/12/2020
Attachment: OKaxjorl_Kawthar.img (contains "OKaxjorl_Signed_ -.pif")

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.GenMlwB
Status:
Malicious
First seen:
2020-10-12 09:14:00 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

img 3573eb2fa96610a18fcb5ae8157af66b5802aa268c66d022f358040c6079ba1b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments