MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027
SHA3-384 hash: 14a9a57d99bf0305a8aa42f655716cb92eb8b3ccaeea474173babf71e38ef89479922690ed8a9241e683597e7b84a9d7
SHA1 hash: 3e35fe3544a321409bc87825303320bbbd0f38f7
MD5 hash: eb39ca7b20582ca5620b61b95dc33fa5
humanhash: mexico-lamp-nineteen-mountain
File name:DEMURRAGE CLAIM.zip
Download: download sample
Signature GuLoader
File size:24'589 bytes
First seen:2020-05-22 09:55:47 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:dXieDE8zzWQY+PFHaBs2wmZ4is5WiA4NQk/KQnrrlclIFQ9OQgE9spIm4/wlMdUs:AejZtw2Aux/K+lyR9OQg34/wlMd/OdTk
TLSH 35B2E1A891A98E50C0D10BFCEC25628C82159D9F9709285FF3A47CE13F62FAC554669F
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: whm.mastertindo.com
Sending IP: 103.103.192.221
From: Stan Lee/Lin & Associates, Maritime Law Office <stanlee@lamariti.com.tw>
Subject: RE : URGENT !!! DEMURRAGE CLAIM
Attachment: DEMURRAGE CLAIM.zip (contains "DEMURRAGE CLAIM.exe")

GuLoader payload URL:
https://ny.yummyeliquid.info/mana.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-22 00:29:58 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
31 of 48 (64.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments