MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 577d729c94d061a2760272b42ad02d915fc63d170580d447a38161659dc90537. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 577d729c94d061a2760272b42ad02d915fc63d170580d447a38161659dc90537
SHA3-384 hash: b1fe9940ba135b5e5f9823415d7372964bde06d54bb8effec086b0af6cafcd61999a41dfc8ac2ebc67a80fd88ec8abc0
SHA1 hash: 64feeba1d4ada9dae9e2b954d844bb7dc518ff58
MD5 hash: 13136b62d3d792ce876cb6b1c6cb4050
humanhash: fifteen-white-orange-equal
File name:BalES001_20204060041.PDF.gz
Download: download sample
Signature GuLoader
File size:75'672 bytes
First seen:2020-06-04 10:47:29 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 1536:cKFzYLah1eXChBTGMQ1Z4jHtB3WIm8YDYv8n5ttSqd7IVjQI:cF6YitQ8L/rmrYDqiVjQI
TLSH 7C73023C8FA697B74517CAEAAB5444F0371C2A36CDA140CEDA87F15B000292556FF9F5
Reporter abuse_ch
Tags:ESP geo GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: yugana.daxa.net
Sending IP: 111.221.42.94
From: Mandiri Banking Financial (Persero) <team3@dskusuma.com>
Subject: Data Saldo Balance ????????
Attachment: BalES001_20204060041.PDF.gz (contains "BalES001_20204060041.PDF.exe")

GuLoader payload URL:
https://cmdtech.com.vn/MY_XXX_VUVHawg214.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 11:35:52 UTC
AV detection:
20 of 30 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 577d729c94d061a2760272b42ad02d915fc63d170580d447a38161659dc90537

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments