MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a97cb61d79347ff6f488c9cf14feb2970893a8c60833af0eb92f22c1daf8fec9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: a97cb61d79347ff6f488c9cf14feb2970893a8c60833af0eb92f22c1daf8fec9
SHA3-384 hash: 8756621f503e0f4bc1826e75a553d1a4a98dfabd35cfd9fd9522a9b559613ee8af0b44eec726e1fe829a22d01b39fe4a
SHA1 hash: c15043345f58f0fa0dd2dcf2a4343e3ce79bf4c0
MD5 hash: ddfab65792b24b3f66f1fbdacaa12647
humanhash: robert-quebec-kansas-hydrogen
File name:PO.IMG
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-28 07:34:58 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:a70nvdTpdjXT2qzzPhvsTvld+AS7TosfwYeSFMqoCqznqG4Y9qWXnx:aQdV7nGTvgs66qUD
TLSH C0452822B756DCB2E64516B0D8E5C5F414E5BC18CA124E2771C97F2F37BA483AE22336
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm87.hanmail.net
Sending IP: 211.231.106.162
From: kpchang <kpchang1@hanmail.net>
Subject: 긴급견적요청
Attachment: PO.IMG (contains "PO.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1lpSf2ph0tWxv5d-KfXV5S-usQUcWjNHP

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-28 07:37:55 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
19 of 47 (40.43%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img a97cb61d79347ff6f488c9cf14feb2970893a8c60833af0eb92f22c1daf8fec9

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments