MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 688ac9fd686d48bc6fec56f27e814c48d7849f548ef14d763dd446b61140c388. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 688ac9fd686d48bc6fec56f27e814c48d7849f548ef14d763dd446b61140c388
SHA3-384 hash: 3cbea3c200943998395454d0f1e367a46ce5abf197f1a308da8a639cab2220dc05a555ad371f888ade4fd70bb74f3f06
SHA1 hash: 44fb379a5aa3fed10d1c4da76197746c4cf6d6bb
MD5 hash: d634d031aa1ac3ed0d4a26ad6295d0ed
humanhash: coffee-tennis-tennis-alaska
File name:SAUDIERSAR.exe
Download: download sample
Signature GuLoader
File size:114'688 bytes
First seen:2020-06-04 06:02:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6393ada2ec783def5ce523b94b856a31 (1 x GuLoader)
ssdeep 1536:gXFSPfxV40qJojvv6kgrKHxLdGKc+o0FDHdZ1gIS2D/SSgki8/ZLgM:BPXsXKVdhjFD9zvAE
Threatray 5'291 similar samples on MalwareBazaar
TLSH D3B37B17EC8E8613D1844BBD3D138E7A3A1CA91D49011FEF71796DAFAD312822C9725E
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mails.grandlogics.ml
Sending IP: 193.142.59.118
From: eran@grandlogics.ml
Subject: PURCHASE ORDER PO.2017174595
Attachment: PO.2017174595.rar (contains "SAUDIERSAR.exe")

GuLoader payload URL:
https://djmixers.co/kcxbin_QlFdCwcYC87.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 00:01:05 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 688ac9fd686d48bc6fec56f27e814c48d7849f548ef14d763dd446b61140c388

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments