MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c7a4804ed163b7ec5f6c142cf185a2ae94adb116b1465533ee0168752aae70fa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c7a4804ed163b7ec5f6c142cf185a2ae94adb116b1465533ee0168752aae70fa
SHA3-384 hash: 627a324e79297a4b49d734bb178097777db2ebf98a10037d32f175aa961832e95096aaaf6e86ec4e7a99e5a69cfc5a26
SHA1 hash: 12646beb14f362ce4f05c72efa9c35fe7b9365dc
MD5 hash: 47d51808acca5f05567d931d9420df1f
humanhash: fillet-kitten-avocado-yankee
File name:Maersk Shipment documents_PDF.rar
Download: download sample
Signature GuLoader
File size:99'733 bytes
First seen:2020-05-18 10:05:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:qdOM9w03A4u4/qocUajbhTiCtRip1J3LR1+fvAb7tYCbXD2M5BPbAHMbak6qA3Sw:tczj/qNJ+8ROBW4fJX/jP00ak+3SUMs
TLSH 32A312A236DE2A17491E4527F4E3C2A0DF2B8D950738F88D2455E77D15FC938088DEB2
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-18 10:35:35 UTC
File Type:
Binary (Archive)
Extracted files:
36
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar c7a4804ed163b7ec5f6c142cf185a2ae94adb116b1465533ee0168752aae70fa

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments