MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d496b4447d60dbc90a2db6962afc3b1a0a385e1333a0c2e0fa0aff3f5f695a18. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



ModiLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d496b4447d60dbc90a2db6962afc3b1a0a385e1333a0c2e0fa0aff3f5f695a18
SHA3-384 hash: e682a483be928990ecf37228d147b8280db91235c54bbff5b799d192251c5963bdb7c222e7da13750f434dfb30e4ab13
SHA1 hash: 3085eeeb6141c543dbfb8b0837bf337b30d1beb0
MD5 hash: 2219142ea1bf2aaaa8142a1a6d567a79
humanhash: rugby-virginia-solar-fillet
File name:DHL Shipment_15.10.20_pdf.gz
Download: download sample
Signature ModiLoader
File size:488'609 bytes
First seen:2020-10-15 17:21:42 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 12288:J8uxUSS1jQZ2i6YJMwEnqWB891bIkVJn8K9GgDQjeeySB5ToN:+0S1ziqijVJL/DQDygVoN
TLSH 5BA4236B694D8206BAEEEA1077FC75E01E92044E6F41E3AC73DC43B47953DCA0AD5386
Reporter abuse_ch
Tags:DHL gz ModiLoader


Avatar
abuse_ch
Malspam distributing ModiLoader:

HELO: localhost
Sending IP: 89.248.168.148
From: DHL Express Service<deliveries@dhl.com>
Subject: Dhl Packages
Attachment: DHL Shipment_15.10.20_pdf.gz (contains "Szrgpwd_Signed_.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Hacktool.Generic
Status:
Suspicious
First seen:
2020-10-15 15:05:00 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

ModiLoader

gz d496b4447d60dbc90a2db6962afc3b1a0a385e1333a0c2e0fa0aff3f5f695a18

(this sample)

  
Dropping
ModiLoader
  
Delivery method
Distributed via e-mail attachment

Comments