MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 68af8e5cbc65757bc6a77455ba8910465ae38a4dcbbfc62163bdbd136cb073be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 68af8e5cbc65757bc6a77455ba8910465ae38a4dcbbfc62163bdbd136cb073be
SHA3-384 hash: aeb21ceffc33a2c8aacc7d02ce98ffc2d5b27ddb3e3db62d8c8e899a85a0fa50dc7d6937b083d2be2670733aabd12751
SHA1 hash: 2dde1be3adaf0140808a5f6c5bf41278ac71fd4e
MD5 hash: 266b3bbc0cfed18828142cc19671bfd5
humanhash: seven-charlie-victor-idaho
File name:SOLICITUD DE MEJOR PRECIO.rar
Download: download sample
Signature GuLoader
File size:36'200 bytes
First seen:2020-05-27 18:26:47 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:U+ayWRa9K8tYo4ySjBsWQIhH7SyGGTdexezjtA:U+eRORfSyWQINSOTHtA
TLSH 41F2E021C16B742C33ACA87CD5166680D5ABADBC4170F2591FA6A88BE03121F32B83C3
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: ibermedia.infortelecomhosting.com
Sending IP: 84.246.211.14
From: Juani Ruiz <juani.ruiz@forjadosorgus.com>
Subject: SOLICITUD DE MEJOR PRECIO
Attachment: SOLICITUD DE MEJOR PRECIO.rar (contains "SOLICITUD DE MEJOR PRECIO.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1f441NuRSv8h5W0qERvZiwziKSYNdaoIa

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 18:37:23 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
13 of 48 (27.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 68af8e5cbc65757bc6a77455ba8910465ae38a4dcbbfc62163bdbd136cb073be

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments