MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e91dab16894900da572b1a8e6204577f552a2daa8cc4acf8f6d906827a3f7d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0e91dab16894900da572b1a8e6204577f552a2daa8cc4acf8f6d906827a3f7d1
SHA3-384 hash: 31d56a64e1cd37f7d3620c803dd8c03f1a14c22fafe05ca2e41167a1017289d8d4cadc2397aa6d3de9ef35beac22f0ea
SHA1 hash: 3e2a7608b0bcd92df95ab29dcb77f14352d69b1e
MD5 hash: c750894d868de6270037091cf2b54f40
humanhash: muppet-edward-emma-red
File name:Purchase Order Ref AIGNEP180520.tar
Download: download sample
Signature GuLoader
File size:57'506 bytes
First seen:2020-05-18 19:56:46 UTC
Last seen:Never
File type: tar
MIME type:application/x-rar
ssdeep 768:q4M6ikN46nxEXIY0QP/EBqgjPrLshfT313sZK31B2fD43mntneKlOrRzxrdhfGAL:G44WGIY0oEEWPrghDCQ3GLnlqzrEc
TLSH 0843024F184C2F5DF35A7B252C653C996D8232FF362697889AFF8106EC317284E57602
Reporter cocaman
Tags:GuLoader tar


Avatar
cocaman
Malicious email
From: Mattia Scalvini <aignep@latorredecoracion.com>
Received: from mail.latorredecoracion.com (mail.latorredecoracion.com [5.56.62.103])
Date: Mon, 18 May 2020 11:43:56 -0700
Subject: RE: Purchase Order Ref : AIGNEP180520
Attachment: Purchase Order Ref AIGNEP180520.tar

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Occamy
Status:
Malicious
First seen:
2020-05-18 20:35:26 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

tar 0e91dab16894900da572b1a8e6204577f552a2daa8cc4acf8f6d906827a3f7d1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments