MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cdcb9a7ab527c755ccb696edddd601707008f56afc85f86d2361a46e12b16361. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: cdcb9a7ab527c755ccb696edddd601707008f56afc85f86d2361a46e12b16361
SHA3-384 hash: 09d7b153c8b1e25f8c5c5179f0a1e389c67847af9ca195be7f871e3fe7caa392c41d0f7d8499c2d91cf5fe61e93575e6
SHA1 hash: 65e990e130b9f0a8f23c0af406916aee2f75a2d3
MD5 hash: f03e70440f4be5f7485e54a21cbd1f9f
humanhash: undress-lithium-asparagus-cold
File name:FOQ20-0514-0064_PT. UNGGUL PRAKARSA PRISMA.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-27 17:29:35 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:XVmvMymngdNDdnSraOFXgJHj7kCBzeQ/d++/ja1Vvf0VZkeNO/JZeODrcA6:lMXVNDdSG2gZkMzeQ/N/0Vvf0QeN1J
TLSH F845F813B5A05CB2FC64CBB208B1AA711D37BC792A150F07754CFB1D5B726CA6AB031A
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.ecomotorhk.com
Sending IP: 162.144.56.225
From: Batgerel Odsuren <odsuren.batgerel.me2@eng.nssmc.com>
Reply-To: odsuren.batgerel.me2@eng.nssmc.com
Subject: Request for Quotation of Screw Decanter Centrifuge_CE1 Project/AA167194000000 (Muhan Technical)
Attachment: FOQ20-0514-0064_PT. UNGGUL PRAKARSA PRISMA.img (contains "order.exe")

GuLoader payload URL:
http://185.94.191.88/bin_qNQJqzF250.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 17:37:07 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img cdcb9a7ab527c755ccb696edddd601707008f56afc85f86d2361a46e12b16361

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments