MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 25f3db15b319d89439a17180cfbc14bbc8677d4bdbf02cfa59fbafcde3ff5cbd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 25f3db15b319d89439a17180cfbc14bbc8677d4bdbf02cfa59fbafcde3ff5cbd
SHA3-384 hash: 41950e041ec582db65c944bc94c4378e283285f944776256499ee9077ffe2aa19420e74ad92c5c2191a18e813c4247aa
SHA1 hash: c65417aff70b63fe490a71caccb901a7864fad99
MD5 hash: 9d249e07a85fa0fa3fcfcfd35f3996f1
humanhash: zebra-quebec-indigo-eleven
File name:Quote009076532020.zip
Download: download sample
Signature GuLoader
File size:32'111 bytes
First seen:2020-05-27 16:42:55 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:hlMwDOA7qVFZrvpuPiScttUO7hRhIK1OiijzFUl+q:zRDO0qVLpuKSmUGz1jijxUMq
TLSH 4BE2E01D31B79CAEB95785BB4C2F1DB0D97DEC73E18D01B6B0A6164249A9390C236C64
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: singnet.com.sg
Sending IP: 160.20.147.182
From: davidkp@singnet.com.sg
Subject: Quest for Quotation (Targets and Evaporation Materials) and Manufacturing Details
Attachment: Quote009076532020.zip (contains "Quote009076532020.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=46B98FE6F0D79519&resid=46B98FE6F0D79519%211842&authkey=ANcfRm-0LjxFJQY

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 10:55:55 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 25f3db15b319d89439a17180cfbc14bbc8677d4bdbf02cfa59fbafcde3ff5cbd

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments