Top Tweets for #ModiLoader
🇮🇹 Campagna #Remcos tramite #Modiloader
🎯 Italia
⚔️ TTP: ZIP > JS > PIF
🦠 #IoC👇
🔗 https://t.co/gJeE9PWOHP (Telegram)

![skocherhan's tweet photo. taqareer[.]tech
#modiloader #Remcos https://t.co/idWccJ6rxa](https://pbs.twimg.com/media/GsEW3TZWwAAMKyc.png)
![skocherhan's tweet photo. lightstone[.]ae
#modiloader @userlolxxl @AbuseAE https://t.co/BBcwAj1knZ](https://pbs.twimg.com/media/GsESMWTW8AAZ5b5.png)

[4/4]
drop url:
176.65.144[.23/ff/kkinng.txt
sha256:
954b611a8e8163b42691ec83d4ff0077ef6f80505a434d03e04c9ae19494ea13
https://t.co/TvHvU6vGnW
🚨 AhnLab warns of ModiLoader (DBatLoader) malware exploiting CAB file headers to bypass email security. Delivered via purchase orders, this threat executes malicious commands. Stay vigilant! 🛡️ #ModiLoader #MalwareAlert #India #ThreatResearch
link: https://t.co/wgP0MBnNsh

Threat actor turns a Cabinet (CAB) file into the Loader. It dropped #ModiLoader (aka #DBatLoader) and ultimately deployed Agent Tesla.
NEOMS_EOI_FORM.cmd (yep this is CAB file)
SHA256: a631e4304cf932de1129cc660fd648125226cfee4059321b4e2048c38b2f9357
Rules & IOCs in🧵
#malware

🚨#Opendir #Malware 🚨
⚠️#ModiLoader
☣️audiodg.exe➡️bbf710c83246092a538128620853d4fd
📡C2:hxxps://maan2u.com/doc/233_Qzzgbhhaaml
ℹ️ C:\\Users\\Public\\pha.pif -WindowStyle hidden -Command Add-MpPreference -ExclusionExtension '.exe','bat','.pif'

Campagne #Malware #Italy Week 35
🔥☠️💣👻
#VIPKeylogger: Bonifico
#Remcos: Spedizioni
#Formbook: Ordini
#AgentTesla: Pagamento
#Modiloader: Preventivi
#APK #Zanubis: Protezione Device
#mwitaly

The overall number of Rescoms samples delivered via AceCryptor nonetheless declined by 75%. It seems that the delivery method of Rescoms in the region has switched to #ModiLoader. We registered several notable ModiLoader phishing campaigns in May, see https://t.co/VsBQEpMndC. 4/6
#ThreatProtection #ModiLoader #malware campaign targeting Small and Medium-Sized Business (#SMB) in #Poland, read more about Symantec's protection: https://t.co/VeJpO7OBQQ
„Die Nachricht sah so legitim aus, wie sie nur hätte sein können.“
Der E-Mail-Anhang war allerdings bösartig und lud #Malware nach.
#ESET Forscher haben neue, breit angelegte #Phishing-Kampagnen mit #ModiLoader entdeckt.
🔎https://t.co/HYeOyT72HB
#WeLiveSecurity

#ESETresearch detected multiple phishing campaigns targeting SMBs in 🇵 Poland, distributing #Rescoms (aka #Remcos), #AgentTesla, and #Formbook malware via #ModiLoader. https://t.co/VsBQEpMndC 1/7
#opendir #trojan #modiloader
hxxp://103.230.121.]50
- 1.exe - Trojan
- Build.exe - Moldiloader
- Crypted.Exe - Trojan
- main.exe - Trojan
- server.exe - Trojan
![RacWatchin8872's tweet photo. #opendir #trojan #modiloader
hxxp://103.230.121.]50
- 1.exe - Trojan
- Build.exe - Moldiloader
- Crypted.Exe - Trojan
- main.exe - Trojan
- server.exe - Trojan https://t.co/3KnEPsg5xo](https://pbs.twimg.com/media/GPJ-O7WXAAAN35X.png)
🚨 Suspicious IP #opendir:
209.126.87[.92:8888
🌐 Domain:
premiere-coal-tonight-procedure.trycloudflare[.com
🔗 File chain:
iz.exe - #modiloader #remcos
🔽
onedrive[.live.com/download?resid=F4D24344D7B13420%21110&authkey=!AL5-vxbOzO8Bd8E
🔽
255_Sraomttecbk
📝 1/2

Dropping a #Yara rule for a new variant of #DBatLoader/#ModiLoader in the wild:
https://t.co/oQdEgTCHk9
#100DaysOfYara

🔓#opendir 147.50.253[.30
🔑Abotihy.exe - #PHEMEDRONE
🔗C2:
💬/bot5358754228:AAE42HAGW1bzIPxU7iVRC_96iDuHcwSjjVo/sendMessage?chat_id=5556872222
🖥️8888.exe - #MODILOADER -> 147.50.253[.30:8888 -> Process.exe
🖥️Client.exe - #NJRAT -> 147.50.253[.30:6522 -> WindowsServices.exe

Here are IOCs for an (as yet) unknown loader. I'm assuming this is #dbatloader #modiloader but I'm not 100% certain.
https://t.co/zudTNx53FR
#ThreatProtection A #ModiLoader campaign has been observed in Easter Europe, read more: https://t.co/PpVhtUkueI #Cybercrime #Cybersecurity #Hungary #Croatia #Russia #Macedonia #Slovenia #BosniaandHerzegovina
#WormsWeeklyIoC have been released!
This week with some new guests:
#AsyncRAT
#BitRat
#QuasarRAT
#RemcosRAT
#XWorm
and the usual
#Rhadamanthys
#Raccoonv2/#RecordBreaker
#DBatLoader / #ModiLoader
#Amadey
6530 new indicators (ca 2020-2023) added to #ThreatFox
Links below:
1/2
#WormsWeeklyIoC have been shared.
New indicators for:
#SystemBC
#Racconv2,#RecordBreaker
#Amadey
#Rhadamanthys
#RedLine
#DBatLoader / #ModiLoader
#Prometei
have been shared via #Threatfox, #OTXAlienvault
and #Github. All links below!
#botnet #ioc #stealer #sharingiscaring
Last Seen Hashtags on Sotwe
dressingroomsex
Seen from Egypt
nolimit()**filter:native_video
Seen from Ireland
น้องเวฟวี่
Seen from Thailand
รีทวิตนัดเย็ด
Seen from Thailand
DevelopmentalDysplasiaofHip
Seen from Brazil
cash_landrum
Seen from United Kingdom
fidanatalay
Seen from Germany
PragueZoo
Seen from Argentina
sister
Seen from Turkey
ድጸልኡ
Seen from United States
Most Popular Users

Elon Musk 
@elonmusk
240.2M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.6M followers

Cristiano Ronaldo 
@cristiano
108.9M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.3M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.6M followers

KATY PERRY 
@katyperry
86.8M followers

Taylor Swift 
@taylorswift13
80.6M followers

Lady Gaga 
@ladygaga
72.2M followers

Kim Kardashian 
@kimkardashian
69.4M followers

YouTube 
@youtube
68.6M followers

Virat Kohli 
@imvkohli
68.5M followers

Bill Gates 
@billgates
63.4M followers

The Ellen Show
@theellenshow
62.5M followers

CNN 
@cnn
61.9M followers

Neymar Jr 
@neymarjr
61.1M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
59.9M followers













![RacWatchin8872's tweet photo. #opendir #trojan #modiloader
hxxp://103.230.121.]50
- 1.exe - Trojan
- Build.exe - Moldiloader
- Crypted.Exe - Trojan
- main.exe - Trojan
- server.exe - Trojan https://t.co/3KnEPsg5xo](https://pbs.twimg.com/media/GPJ-O7QWkAAW1NW.png)
![RacWatchin8872's tweet photo. #opendir #trojan #modiloader
hxxp://103.230.121.]50
- 1.exe - Trojan
- Build.exe - Moldiloader
- Crypted.Exe - Trojan
- main.exe - Trojan
- server.exe - Trojan https://t.co/3KnEPsg5xo](https://pbs.twimg.com/media/GPJ-O7LXIAARSYz.jpg)
![RacWatchin8872's tweet photo. #opendir #trojan #modiloader
hxxp://103.230.121.]50
- 1.exe - Trojan
- Build.exe - Moldiloader
- Crypted.Exe - Trojan
- main.exe - Trojan
- server.exe - Trojan https://t.co/3KnEPsg5xo](https://pbs.twimg.com/media/GPJ-O7KWoAA1Ngg.png)



