MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3bc97524433efa4870005e3e51ed2dc9e9574448b4dd9c9a6edf6c4674d1c495. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3bc97524433efa4870005e3e51ed2dc9e9574448b4dd9c9a6edf6c4674d1c495
SHA3-384 hash: 12f87bc07c90c80d883126f20544c559db5d59515339e1aef315b9bbdc5bd616a6ac42d7237a57cc454a185465723803
SHA1 hash: e02dea2aa54947b3bff5c74796a9767c593998ac
MD5 hash: f83e8b8c1a64305b4e0f62f575c293e0
humanhash: juliet-fix-texas-kansas
File name:Downloads.img
Download: download sample
Signature ModiLoader
File size:1'441'792 bytes
First seen:2021-06-25 06:20:21 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:hdd+IDlXMiKYI/rv5zsThfj3lDx4TSVnb7x3cKf/jhgnfPnbetkkkSd:hdd+GtKYI/9wTBVSTSpb7x3c4/jld
TLSH 8C657CE1B75004F1E517763ADC1AB6E5B43C7EE0291498C27AE87E0E3F35782745A06B
Reporter cocaman
Tags:DHL img ModiLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
119
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
SUSPICIOUS
Threat name:
Win32.Exploit.Generic
Status:
Suspicious
First seen:
2021-06-24 13:57:46 UTC
AV detection:
8 of 46 (17.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

img 3bc97524433efa4870005e3e51ed2dc9e9574448b4dd9c9a6edf6c4674d1c495

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments