MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bd5e7443c888f2059c81b735be3da1a516d6142b22ca3b586c38b50c4b74879. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 6bd5e7443c888f2059c81b735be3da1a516d6142b22ca3b586c38b50c4b74879
SHA3-384 hash: 4212c999918697ef6be93f542998046f5f0c37d2162536ace06a4ea6b0b26151c0715482665897a9bc8408e21c97354e
SHA1 hash: bbfba505ca8df91ecbde0d34183fc2b3538c3b4a
MD5 hash: dfcc57a4a0672cd610a7276d9047ea77
humanhash: apart-maine-nebraska-tennis
File name:PROJECT MATERIALS, MACHINES AND EQUIPMENTS.img
Download: download sample
Signature GuLoader
File size:147'456 bytes
First seen:2020-05-21 08:39:48 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:ip1pryKgBODfifkZFO8U4Q0Q0OB9vJLXLV4I3xGyjx4pUU6PVbHfEmuNH2Q:GyFUb1F5UZvR/GI7cmK1
TLSH 93E32963F9B45EB8EA6447F1A93282100523EDF105B60B0BB1CD7A0D6F77A8B7920717
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm80.hanmail.net
Sending IP: 211.231.106.155
From: SARAH KWON <jwtotal7447@daum.net>
Subject: [MFC. PROJECT] 5202020[MATERIALS, MACHINES AND EQUIPMENT]ASCON CO.,LTD
Attachment: PROJECT MATERIALS, MACHINES AND EQUIPMENTS.img (contains "PROJECT MATERIALS, MACHINES AND EQUIPMENTS.exe")

GuLoader payload URL:
http://ukaimc.webredirect.org/uploud/5bab0b1d864615bab0b1d864b3/bin_ntkZMpLO186.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-05-21 09:36:28 UTC
AV detection:
12 of 48 (25.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 6bd5e7443c888f2059c81b735be3da1a516d6142b22ca3b586c38b50c4b74879

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments