MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cae5e5e548f68866d8203773e07c4f91d544ddcca1a76e8e0e304a8a0c7d95c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: cae5e5e548f68866d8203773e07c4f91d544ddcca1a76e8e0e304a8a0c7d95c1
SHA3-384 hash: ff7ea0a2b17ad61f636c13d8088517083bd7a7bbf7279e42f3418c16e3fb972a7ddf501d2012a9d3cbbbc482e0142796
SHA1 hash: c0ce417769fc6a0b8a557c95aacc8dc4ffccdccc
MD5 hash: c67c0c393170eec4ec597b7fcc827606
humanhash: magazine-zebra-iowa-tennessee
File name:FRA2000856.zip
Download: download sample
Signature GuLoader
File size:29'628 bytes
First seen:2020-05-26 07:25:08 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:37REC1lwuoQP2uTbpesfk9pTK4awKWI11+y8Ydb:LRJ/349hujKy8Ydb
TLSH 4BD2F1E2CD0F4BB8C7CDB7F5E88C71FE301983905529F654B8092CC546D66291B16ADA
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: portalmw.com
Sending IP: 188.165.128.19
From: Administracion <info@fedizseguros.com>
Reply-To: info@fedizseguros.com
Subject: Factura.
Attachment: FRA2000856.zip (contains "TOSSEHOVEDERNEPR.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1pxcExleULb3wQy5Cn5i2mSITXGnl8KZ1

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-26 07:36:37 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip cae5e5e548f68866d8203773e07c4f91d544ddcca1a76e8e0e304a8a0c7d95c1

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments