MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdbf5ef388b6a222c784994789b593d2213d1b491aa02963bedf64cac89fba3b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cdbf5ef388b6a222c784994789b593d2213d1b491aa02963bedf64cac89fba3b
SHA3-384 hash: 0c4f92479c9cf80ec1af4945f323d8b1f190750f54fdc50a3c20216fe760d3b536bd2acb9d5a713dd51481abd5f42abb
SHA1 hash: 40c294d3afe6232c5ac71fd57d9163c09d1fc25d
MD5 hash: 58d22ca1e84f9db5d38990e7cef4b76c
humanhash: idaho-timing-sad-bluebird
File name:listed Product.zip
Download: download sample
Signature GuLoader
File size:28'335 bytes
First seen:2020-05-21 10:30:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:ju6bqZVkTxwG54vRR2I+LhpMhV2FccXwLmFoV+:ju6OZVkO/R2I+LhswFJUmFa+
TLSH 7ED2E1D0A699C12753F6C3502DE20E3CA06ACE0BF597C952319675DF21F1CA40E6F2BA
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

From: mr Grace <grace.yeboah@movis-ghana.com>
Subject: NEW INQUIRY FOR ORDER
Attachment: listed Product.zip (contains "listed Product.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1aEbAIx0nA_D0lqSvGd-MKFjH73cWlDOK

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-05-21 10:37:12 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip cdbf5ef388b6a222c784994789b593d2213d1b491aa02963bedf64cac89fba3b

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments