MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2b551d98f7cfab5065bab4df3eae19af497e729a5dbe63655a8527988fb28ca1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2b551d98f7cfab5065bab4df3eae19af497e729a5dbe63655a8527988fb28ca1
SHA3-384 hash: cfbb92356f057011fb9c3cfcdcd32281f0ce6e240e2342c80c3a312be56bbe7397c5d6e73ba150dfb2f3c595ada4b0d5
SHA1 hash: ce390de81db82dc35b8eb675257de94fa5be3f72
MD5 hash: cd02e269190b5f70b49b03de928b315e
humanhash: east-montana-edward-kentucky
File name:order 52242020.pdf.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-05-22 10:25:03 UTC
Last seen:2020-05-22 10:52:20 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e6ad31a501b7ebd445e43e3d9e6dbdde (1 x GuLoader)
ssdeep 768:Iyabd0qm9ish/3K0Azm0WDYYcNRRVJG2/MNWnya60J3rJ6nwlg:5abajiQ3wVYsVgWyabYnd
Threatray 83 similar samples on MalwareBazaar
TLSH A393182AF644DD66CA750FF06E328B6C046BBC306921CB0375DA3B2D6933A9D9435357
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.euromaster.es
Sending IP: 82.223.70.126
From: Evangelos Fasilis <tdroggitou@deloudis.gr>
Subject: Re:New Order
Attachment: order 52242020.arj (contains "order 52242020.pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1jMZLcuxisSMShYRaNdb03Q0Hh6mmbwio

Intelligence


File Origin
# of uploads :
2
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-22 10:00:22 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 2b551d98f7cfab5065bab4df3eae19af497e729a5dbe63655a8527988fb28ca1

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments