MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c18e29bb3df82a2c80d2b4679e079972ca301b239131abff0d9dfdf3917ea2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2c18e29bb3df82a2c80d2b4679e079972ca301b239131abff0d9dfdf3917ea2c
SHA3-384 hash: 87e19f804d66cde735fea545d6ec50923b0a1cfff346aedb35ca5c1c52d1c0810b2d145198e248e9a06d7fab2a8abdd9
SHA1 hash: 2ceb4591706d673259936dc9cceff1ac8273ed9a
MD5 hash: 3f46f856950c25e72add9fc6a3b55d3a
humanhash: alabama-three-princess-september
File name:RFQ DOC 7800000174.IMG
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-28 07:00:50 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:yAy9PteiiInxdRFgS1qNTKFaK/OZIua0xLZ4U5i/YKEVoyF:ynteiDcgtFaK/DuVxu3+ou
TLSH AF450A2775E08CB6EF3489710D625EE12D37BD216A424F0F358EFB0D2B362A739A1645
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: nsmail.psa.gov.ph
Sending IP: 202.78.94.66
From: Nashad Noor Nilambra <nasad.noor@cppmde.com>
Reply-To: Nashad Noor Nilambra <rahmati@kitoenterprises.co>, Nashad Noor Nilambra <sw4629342@gmail.com>
Subject: Project: BAB Integrated Facilities Project (BIFP) Closing Date: 30th May 2020
Attachment: RFQ DOC 7800000174.IMG (contains "Liberationistin.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=F5533CD060D35070&resid=F5533CD060D35070%21163&authkey=AINnNbxdElpMFHs

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-28 07:36:11 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 2c18e29bb3df82a2c80d2b4679e079972ca301b239131abff0d9dfdf3917ea2c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments