MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4df6e6f237e568423c4c84586788189d22354849d558ace6fdce6bec5b9cca10. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4df6e6f237e568423c4c84586788189d22354849d558ace6fdce6bec5b9cca10
SHA3-384 hash: aa8f941677980a1b2ef7f51a7aabc79664bf3ed3446fe4de77921e4252eb0a88bf1bb5b578ffb0d2aa8e509f586ab639
SHA1 hash: 1ebd39359e9dead61b7e55353648b8ac3d7a5f79
MD5 hash: 872faa32b2f89858e9bb71affd33b192
humanhash: grey-single-speaker-oven
File name:11-4-2020_06-59-10-PM.zip
Download: download sample
Signature ModiLoader
File size:1'225'450 bytes
First seen:2020-11-05 09:19:18 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:C+kXJyJ2+gkOXZ8Wp/PDSz/+kXJyJ2+gkOXZ8Wp/PDSzk:pyyE9keeWpDSqyyE9keeWpDSg
TLSH 344523E1DC52AC5DE6D555B473A8F8E756A7C978FC01E2044C0E0D86FBC9813AAB23E4
Reporter abuse_ch
Tags:geo ModiLoader TUR zip


Avatar
abuse_ch
Malspam distributing ModiLoader:

HELO: tur2.hipotenus.com
Sending IP: 213.159.30.161
From: turgut.guleryuz@mimtech.com.tr
Subject: Re: Emailin
Attachment: 11-4-2020_06-59-10-PM.zip (contains "acil siparis.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-11-04 20:32:39 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

zip 4df6e6f237e568423c4c84586788189d22354849d558ace6fdce6bec5b9cca10

(this sample)

  
Dropping
ModiLoader
  
Delivery method
Distributed via e-mail attachment

Comments