MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91cdb83cec82b49276450d15264766977fa78b39a5a682d0b421077ad2121d31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 91cdb83cec82b49276450d15264766977fa78b39a5a682d0b421077ad2121d31
SHA3-384 hash: 2f2f72528ed1063fdfa4a4f0bbd5b9537816578b3e89c042ffc1c355a409bb2cc6336876ad3243ebb2d2e0c11908de4e
SHA1 hash: 94af6573073f25b35d61a0fd33c426efc5b04aae
MD5 hash: 5d139a06aaccebb3bf02fe722b6e1149
humanhash: mockingbird-robin-eight-alpha
File name:MTO_QCXP00004_04R4_Al. Alloy Plates GR 5083_H321.rar
Download: download sample
Signature GuLoader
File size:42'557 bytes
First seen:2020-06-02 11:16:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:t4Ju9uBvcFPD/eDafFX1oS1Av5IfWcO2aKNE5Y9prAu:tWFcFPDnfFXiSmRMrNE5o9Au
TLSH 5A1302CB1646631C6D5FAB78E9B389FC075D5404101BE0C1BBC9034ABD82CAAD569DF9
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.cesosenintl.ml
Sending IP: 64.188.23.5
From: Sanjay Anchan <sanjay.anchan@protosindia.com>
Subject: Firm requirement—Rafael—Raw Material—QCXP00004/03 R3 & QCXP00004/04 R4
Attachment: MTO_QCXP00004_04R4_Al. Alloy Plates GR 5083_H321.rar (contains "MTO_QCXP00004_04R4_Al. Alloy Plates GR 5083_H321.exe")

GuLoader payload URL:
https://secure.drivebookers.com/kali_UfquusEKt204.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-02 11:37:31 UTC
AV detection:
22 of 46 (47.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 91cdb83cec82b49276450d15264766977fa78b39a5a682d0b421077ad2121d31

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments