MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df1616ab476cf594ba06aa5b0b6f03a249545e6b383c871effee0bc7bd4d2212. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: df1616ab476cf594ba06aa5b0b6f03a249545e6b383c871effee0bc7bd4d2212
SHA3-384 hash: 267d1b266133ccdc268cf6958aa677adfb6f7fcf951dfa00280698fe7e36d99ea463f69fae8ac432ccbbca4cc84a1455
SHA1 hash: d21d7da6bd01aa0ef47e00ea808c20346fa379dc
MD5 hash: 3bfa4667e45e971b54f1e1e6ee88d501
humanhash: emma-mexico-quebec-butter
File name:Invoce.lzh
Download: download sample
Signature GuLoader
File size:24'475 bytes
First seen:2020-05-28 18:05:52 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:eir8XdMAukIG83x/KDD+RBCQl7LhdqUTKNJcrdbKemwbcxaTqEnSMgm:eioV7Iji+TCQ1FgJcrZMwbcxaTqEVJ
TLSH C8B2F24B3283712955F5DC4D503E65E1832D6C5DBA683196082F842B46B836F6CFCBEB
Reporter abuse_ch
Tags:GuLoader lzh


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.sunhilltopvilla.com
Sending IP: 66.45.250.72
From: jana<work@sunhilltopvilla.com>
Reply-To: work@sunhilltopvilla.com
Subject: AIDC Invoice 038652 and 038653 QSB-18-1547
Attachment: Invoce.lzh (contains "Invoce.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=02E98840A4C9FD6C&resid=2E98840A4C9FD6C%211172&authkey=AEcgmc__P8n8irw

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Azden
Status:
Malicious
First seen:
2020-05-28 18:37:02 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
15 of 48 (31.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar df1616ab476cf594ba06aa5b0b6f03a249545e6b383c871effee0bc7bd4d2212

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments