MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d36be9fcdd17d0b4156bf377b8fdb656101a343f7ca1d259d12aa9fefd521b6b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d36be9fcdd17d0b4156bf377b8fdb656101a343f7ca1d259d12aa9fefd521b6b
SHA3-384 hash: 408b3d632e43d95d4bf9c7921757d420b56e8407945eccba94f1ec601b5c3c2aed293c0b4dfd4c0cadb8087da242458c
SHA1 hash: 29067b6102ae82bcc04f94137d22323efee05835
MD5 hash: aaa3980ea70d72662bde8c72ed7074ab
humanhash: alaska-hotel-grey-kitten
File name:El nuevo pedido esta en la lista adjunta.zip
Download: download sample
Signature ModiLoader
File size:496'706 bytes
First seen:2020-10-06 07:33:12 UTC
Last seen:2020-10-06 07:53:16 UTC
File type: zip
MIME type:application/zip
ssdeep 12288:LDy7JpAJz4elD3ZYf9M2Ad/htv/t0MS0X8d6LJW0+F9:LLJz/3ZY+Ztv/2H0X8dGJz+F9
TLSH 04B423FC3C0E550DE1530F89B0F6DE8DDE8A8625F67DA71403F6689AD660E19F259C20
Reporter AltraSvista
Tags:formbook modiloader

Intelligence


File Origin
# of uploads :
2
# of downloads :
107
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.Remcos
Status:
Malicious
First seen:
2020-10-05 14:51:34 UTC
AV detection:
21 of 29 (72.41%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

zip d36be9fcdd17d0b4156bf377b8fdb656101a343f7ca1d259d12aa9fefd521b6b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments