MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8d9417b763ac5b1d32e529536a14db3fe8bed0e20e73957035abf1399c93a67. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c8d9417b763ac5b1d32e529536a14db3fe8bed0e20e73957035abf1399c93a67
SHA3-384 hash: 798a7b4f599c2267bbad6888a7fc0da0830a0ad057f4f520e8c360a8966aa0df152e155fc70d30b13611a86ba250daad
SHA1 hash: 13f09c7df8b7cbbbe620e4499c727b49df22c65d
MD5 hash: 84048a12eac8c59b730d398a9a6efaf5
humanhash: beer-georgia-enemy-wisconsin
File name:RFQ_DOOYOUN CORPORATION 긴급 ìƒ ì‚° 요청-pdf.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-08 12:05:03 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:PeysfNpuRnnPilTjATM7pscXayn+mGLdBdB65ISvTkRXQJtEWx4Be3KOa2jLUzHd:PeysFY6TjMOOYST2ISv0goKKmjLJa
TLSH E445AF036D04C651F04182B09DA38B9623666D296D426BE73A5E2F9FEF31BC25DF930D
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.ecomotorhk.com
Sending IP: 162.144.56.225
From: Jaeho Lee <ydchoi1@naver.com>
Subject: DOOYOUN CORPORATION Emergency Production Request
Attachment: RFQ_DOOYOUN CORPORATION 긴급 ìƒ ì‚° 요청-pdf.img (contains "order.exe")

GuLoader payload URL:
http://149.255.36.133/bin_PqLAqQjAza233.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 12:06:10 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img c8d9417b763ac5b1d32e529536a14db3fe8bed0e20e73957035abf1399c93a67

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments