MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b494e85c58028bb5c6435e7f67edb0e08632a67124a8d03e8ac11421a4e6f40b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: b494e85c58028bb5c6435e7f67edb0e08632a67124a8d03e8ac11421a4e6f40b
SHA3-384 hash: 50f599c4dc3713db1546bfb7f1720f9d74956f12859271d2996cc6849805494e18a81cc863e8d4870fac19a863263738
SHA1 hash: 39df77bfee93a430b83fedb2e0b7896532de01f2
MD5 hash: bb29c48c263c44262c4c30ddc04ba655
humanhash: virginia-low-alabama-seventeen
File name:purchase order.gz
Download: download sample
Signature GuLoader
File size:25'117 bytes
First seen:2020-05-21 10:31:35 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 768:2olnwUWc5e3ZPWatvuGbU7dLcm7QhYM66EMlpcv:2InwPpWatvNE1cGQuM7lpcv
TLSH D0B2D1714A12751BFC7D3ABC50C575B304623650DADEADA54C4E643A763E6DE302E0CA
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: shbc10.ultina.jp
Sending IP: 218.40.207.10
From: Apiraporn <purchase.gr@euronav.com>
Reply-To: purchase.gr@euronav.com
Subject: Purchase order
Attachment: purchase order.gz (contains "file.exe")

GuLoader payload URL:
http://creativewg.com/feed_yLymE159.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 10:37:09 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
14 of 48 (29.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz b494e85c58028bb5c6435e7f67edb0e08632a67124a8d03e8ac11421a4e6f40b

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments