MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 edc36bfef2c4b6b3121b2bc03c24bcf462a08a2b776e17bd00130a78e9d97748. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
ModiLoader
Vendor detections: 3
| SHA256 hash: | edc36bfef2c4b6b3121b2bc03c24bcf462a08a2b776e17bd00130a78e9d97748 |
|---|---|
| SHA3-384 hash: | c89ba271c2aff7ef74494a0439df99d41ac161b2a4787eda9b26ac89eda341d4716befc691c9da87c16a250df14f4751 |
| SHA1 hash: | a83a50e4e2d72d1001bc84f36fab9fe8799c4c7d |
| MD5 hash: | 4781c65762016dbb1e624418e6ac2d1b |
| humanhash: | mexico-potato-spaghetti-jupiter |
| File name: | Report for COVID-19 Non-Complaince Doc.img |
| Download: | download sample |
| Signature | ModiLoader |
| File size: | 1'441'792 bytes |
| First seen: | 2020-10-09 17:24:02 UTC |
| Last seen: | Never |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:6uDiCtaeLlIPFPqqDgNYN5u/g7GWDftVHa0F8Gq8wjVQsX3erB9p:9GCblI9PqqDCYN5BaWT7dwJQ |
| TLSH | 64657D32E2915437C1272A749D1B9765AB39FF102E28AC467BF41D5C5FF97803C2A2A3 |
| Reporter | |
| Tags: | COVID-19 covid19 geo img ModiLoader ZAF |
abuse_ch
Malspam distributing unidentified malware:HELO: rdns4.carepayy.xyz
Sending IP: 151.80.255.188
From: covid19notify@health.gov.za
Subject: Action Required: Customer Report for COVID-19 Non-Compliance
Attachment: Report for COVID-19 Non-Complaince Doc.img (contains "Customer Report on COVID-19 Non-Complaince. Doc.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
151
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Remcos
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.