ModiLoader Malware Analizi
Dosya Ozellikleri
SHA256: d228e18c458c31492267b3167e1bde3b8702de493ea612d0ecf400835f490982
MD5: f3f28798bf7cc0bd1e1a44e3c956a253
Dosya Tipi: exe
Boyut: 1,002,496 byte
Ilk Gorulme: 2022-04-13
AV Imzasi: ModiLoader
Imphash: e70ebf13be6a24042d117ba668cc8eb8
Raporlayan: GovCERT_CH
Etiketler: exe, ModiLoader, xloader
Statik analiz: metadata tabanli (ornek indirilmedi)
ModiLoader — Malware Profile
ModiLoader. TFG0890000001.exe logistics lure. Microsoft.TeamFoundation Azure DevOps SDK embedded. MySql.Data.MySqlClient MySQL connector. Possible Azure DevOps C2 channel.
Technical Details
Varyanta gore C/C#/VBS/PS1, anti-analysis (VM/debugger check), persistence (Registry/Task Scheduler/Startup folder), payload decryption ve injection (shellcode/PE), fileless execution teknikleri
Capabilities & Behavior
IOC List (1 indicators)
# FILEPATH
d228e18c458c31492267b3167e1bde3b8702de493ea612d0ecf400835f490982
| Type | Value | Note |
|---|---|---|
| filepath | d228e18c458c31492267b3167e1bde3b8702de493ea612d0ecf400835f490982 | PDB |