MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aac127abd6acac09a855ac5084a5dc9965179625b49b18f5fe597d269a1d9f17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: aac127abd6acac09a855ac5084a5dc9965179625b49b18f5fe597d269a1d9f17
SHA3-384 hash: 48cd71cfcc121a6af64cac17f81575c8354c112f1cf1c14ddd9c82076dedec23c6609fdbcb26edce5adceb2bdb4488be
SHA1 hash: e8a63ed5550f043ffa0f499736421618d5ed2e98
MD5 hash: dc5b6b4c272411afc7ffa6dce7d28635
humanhash: east-ink-alaska-whiskey
File name:INV00531.gz
Download: download sample
Signature ModiLoader
File size:404'709 bytes
First seen:2020-10-08 04:35:34 UTC
Last seen:2020-10-09 04:59:38 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:quhvmJhbhqwUW8IcvilGrmONo8gaBivpOHOGhSU4Nv1G/8kpW1Pl:quhvmJhb4wUW8Itl+ptgBES2/bUl
TLSH 268423BFD020B1367418846BFF2BF69533971B43D479A9B896129088BC3FCA47747A61
Reporter GovCERT_CH
Tags:ModiLoader

Intelligence


File Origin
# of uploads :
11
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.RemcosCrypt
Status:
Malicious
First seen:
2020-10-08 04:37:05 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

zip aac127abd6acac09a855ac5084a5dc9965179625b49b18f5fe597d269a1d9f17

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments