MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 78caff8a4f7ca46069095397b4565b287c710e5510b8de339c24c0811439f37d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GuLoader
Vendor detections: 3
| SHA256 hash: | 78caff8a4f7ca46069095397b4565b287c710e5510b8de339c24c0811439f37d |
|---|---|
| SHA3-384 hash: | 0096bc293f725e53e460f0875d852ba9bb8c9c4363f87ca070c432b6faecba4f79ab0572bd36d14aec39a3c249a856e0 |
| SHA1 hash: | 126a2b928330e942b741b7304a1e034c7708ba39 |
| MD5 hash: | df57091ea5ce24dbb603f7921d59c7df |
| humanhash: | december-double-beer-harry |
| File name: | Shipping Docs_pdf.gz |
| Download: | download sample |
| Signature | GuLoader |
| File size: | 66'690 bytes |
| First seen: | 2020-05-18 05:58:18 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 1536:6cxlgsDs+ClcKig5KKAKXXXXYi9/lrSygp3Q4/U9wYd0P:6cHg4PuNiqH3B/lm7s3u |
| TLSH | 5853029C4BB8D1B38F7C0267B5C81C8F01E0B698A1982442795C747E5A6BB15CFE7376 |
| Reporter | |
| Tags: | GuLoader gz |
cocaman
Malicious emailFrom: MAERSK LINE <customerservice@maerskline.com>
Received: from eep1-15.nexcess.net (eep1-15.nexcess.net [104.207.230.81])
Date: Sun, 17 May 2020 19:23:52 -0400
Subject: MAERSK LINE SHIPMENT DOCUMENT
Attachment: Shipping Docs_pdf.gz
Intelligence
File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 06:35:51 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
25 of 48 (52.08%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.