MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e6acc2cd69014ea5f71b50328997193ed91eae000033ccffd7b6e6a8b17291b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5e6acc2cd69014ea5f71b50328997193ed91eae000033ccffd7b6e6a8b17291b
SHA3-384 hash: 4e2a85a13fcea63d052dd44e5796a8210b2b330ff48dd5b68efa81b4cf1f9c99912b15d03de23f2f89e311eaa4d6b62e
SHA1 hash: a6d499156b41ff86442401682e1947e3cf68f3f3
MD5 hash: 08202accb0f84a3a5235b1a7413dd1dc
humanhash: juliet-snake-massachusetts-connecticut
File name:OOCS DI- 209871 CB.iso
Download: download sample
Signature GuLoader
File size:151'552 bytes
First seen:2020-05-05 11:15:46 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 1536:G4/K1kkkaFjfSyHdVlGi7iBJsxHX83j9FB6:RKWAS5BM
TLSH B7E3D4016EB4EC22E51479B1DB6AF6AED713AC301936481731CD7A2D2F37A429D3532E
Reporter cocaman
Tags:GuLoader iso


Avatar
cocaman
Malicious email
From: Precision-Makers <info@precision-makers.ch>
Received: from precision-makers.ch (hwsrv-722254.hostwindsdns.com [192.236.193.209])
Date: 5 May 2020 04:03:53 -0700
Subject: Re: Cracker Barrel - OOCS DI
Attachment: OOCS DI- 209871 CB.iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Geniso
Status:
Malicious
First seen:
2020-05-05 11:36:56 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso 5e6acc2cd69014ea5f71b50328997193ed91eae000033ccffd7b6e6a8b17291b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments