MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ec4855660b623164be8cbd892c4125175912a9a8ee4ea3e4d76d1a357d6f575. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2ec4855660b623164be8cbd892c4125175912a9a8ee4ea3e4d76d1a357d6f575
SHA3-384 hash: fb077ce0ed692ec558dd88ad99f0d0cb7cd7615bdbd7f12949b9cf4b5a39e3011a36b8925d1d796f8f08b9efed5a09fb
SHA1 hash: f8d51b99fac126d6b1ec7810243efecdb9a1c8ab
MD5 hash: 7cc13969fc4c3fc4b543e16f247263c0
humanhash: ten-orange-vegan-fix
File name:DHL_AWB 9284730931.rar
Download: download sample
Signature GuLoader
File size:41'201 bytes
First seen:2020-06-02 10:59:52 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:+PujPsxiTz7OlWrLNV58MT+fdS3vnwxbICWVnhli04gC/CQXmSj7kox:LjNTeKNVubVS/wxbBWVDi0S//mSj7D
TLSH E70301C69BA2CA9728983370470EAB3654DCCADBBD0B543F3406F51181DC20A42F3BAD
Reporter abuse_ch
Tags:DHL GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.gtrit.com.my
Sending IP: 103.18.246.122
From: DHL Express<eawb@iddhl.com>
Subject: EAWB Notification
Attachment: DHL_AWB 9284730931.rar (contains "DHL_AWB# 9284730931.exe")

GuLoader payload URL:
https://qif.ac.ke/flow_AoGPhiVz245.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 04:02:25 UTC
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 2ec4855660b623164be8cbd892c4125175912a9a8ee4ea3e4d76d1a357d6f575

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments