MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 913254b45e54bde9abe1d3873b351d38a3e87d8fa0f2b32488146ec1da73e85b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 913254b45e54bde9abe1d3873b351d38a3e87d8fa0f2b32488146ec1da73e85b
SHA3-384 hash: a6f2537fdb84d8241c64aabdce7a87d20db0f21e5ae3ae5d0622768e8f27fcee829e5684050cbe21ba1b2b70eff2da56
SHA1 hash: 44ad7da09618b05bf5fed1a8a336dcd791926404
MD5 hash: a33624c9452c3e04d283805f55365a8a
humanhash: butter-double-london-cold
File name:Doc00118871655141998.img
Download: download sample
Signature ModiLoader
File size:1'572'864 bytes
First seen:2020-12-26 08:09:28 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:9ktJiYAb4e6ru732S0W9Xfnv3ZhM7wISwiscMnwUKE0:9GJNt8NNZ3742VUC
TLSH 52753921227884B7E13DED368BDD93DC4D9C2D1D19792409B2AE79B8DB3F143A4391CA
Reporter abuse_ch
Tags:img ModiLoader


Avatar
abuse_ch
Malspam distributing ModiLoader:

HELO: smtprelay.hostedemail.com
Sending IP: 216.40.44.243
From: Build-Mate PLC <eorder@buildmate.com.sg>
Subject: Build-Mate PLC- Please Advise on Availability of Enclosed PO
Attachment: Doc00118871655141998.img (contains "Doc00118871655141998.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
534
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-12-26 08:10:07 UTC
AV detection:
9 of 47 (19.15%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

img 913254b45e54bde9abe1d3873b351d38a3e87d8fa0f2b32488146ec1da73e85b

(this sample)

  
Dropping
ModiLoader
  
Delivery method
Distributed via e-mail attachment

Comments