MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc2e9afbdf92bdb7e16bb3b4f433379439b64723a1476f797fbebcd54a600478. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cc2e9afbdf92bdb7e16bb3b4f433379439b64723a1476f797fbebcd54a600478
SHA3-384 hash: df39a76e38233c719b375cae6ba53babed7016a1230726fbe547ff1046b62bb68f4e970ab825f785325da6ae22cc9053
SHA1 hash: ee87c7030606f64efd52b22af277b46de7e6cfba
MD5 hash: 782ecd7c8526d798a355c499affb79f3
humanhash: shade-utah-bulldog-zebra
File name:PO.2017174595.rar
Download: download sample
Signature GuLoader
File size:74'301 bytes
First seen:2020-06-04 06:02:45 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:PQoXpAn8PgWgg7cNednqT8G6QHHjQqJWdy14NjXGZscxjW:P5Jgk08gHMg6ugjXGZ5K
TLSH FB73020C5E72999361925DB81BB3D0178D1484332F3833787AEC9EC7BBA53A384AB5C5
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mails.grandlogics.ml
Sending IP: 193.142.59.118
From: eran@grandlogics.ml
Subject: PURCHASE ORDER PO.2017174595
Attachment: PO.2017174595.rar (contains "SAUDIERSAR.exe")

GuLoader payload URL:
https://djmixers.co/kcxbin_QlFdCwcYC87.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 03:17:30 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar cc2e9afbdf92bdb7e16bb3b4f433379439b64723a1476f797fbebcd54a600478

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments