MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc
SHA3-384 hash: 4c2b756fba4dfa8402a7b761f8112eab9b85393b4fd999ade4c77208c996a3c9b6f175d9bc4b86157be5a47fa01e7ce7
SHA1 hash: b45ae97e89a44f8a0d602b59fba4c17c611e7820
MD5 hash: 0404c11054da08695c4e159e71316e6b
humanhash: summer-rugby-sink-india
File name:Payment Copy.zip
Download: download sample
Signature GuLoader
File size:27'663 bytes
First seen:2020-05-22 10:20:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:Ov+KhNxveZC3De4w9NEOtOYFRTQ7BeIyWX9GarRT:CTveZCTe4wn2mlQQIyWXx5
TLSH D5C2F1CC5130BB53FB119678F11141DBB59C61E11399EBBC9AD51E0676074FB11F8E22
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mx.shi-ig.com
Sending IP: 217.61.123.234
From: jeff@shi-ig.com
Subject: Re:Payment copy
Attachment: Payment Copy.zip (contains "Payment Copy.bat")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1dje1f5MKekSEqm5EHUuqTF-64jLzc6Hn

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 22:17:56 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
25 of 48 (52.08%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments