MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c578dbcd89732a22af6b96d37f20ef9d04d6c328e0d89949ba8125d3c67d11cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c578dbcd89732a22af6b96d37f20ef9d04d6c328e0d89949ba8125d3c67d11cb
SHA3-384 hash: fe3ab5e693b766fef44fd010f25054dfef81c84267f36192f4873b0f976cd21eb5365649284486233560d4669a20faf1
SHA1 hash: b66f202577c4008e70d0cc60410d6ae6668073ab
MD5 hash: 7a6b015dd72b182ec6cdd5260f0e7dcc
humanhash: happy-paris-speaker-paris
File name:DHL Shipment Doc.ace
Download: download sample
Signature GuLoader
File size:28'380 bytes
First seen:2020-05-27 09:19:22 UTC
Last seen:Never
File type: ace
MIME type:application/octet-stream
ssdeep 768:cPF54NuJQPI8cogXkhtwyqSncFIZSZ/p8IvDr:oeuQ5aXkr52IZSZiIvDr
TLSH FFD2F12692684B7C7D7314EFD32B5BE3786865613A283026C0DF44B3E378BA56C1D532
Reporter jarumlus

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-05-27 09:37:57 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
16 of 31 (51.61%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

ace c578dbcd89732a22af6b96d37f20ef9d04d6c328e0d89949ba8125d3c67d11cb

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments