MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df4d24a276ca00cd58a53bb275f6e5344cf223580ed5f0175fa98faec8fce772. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: df4d24a276ca00cd58a53bb275f6e5344cf223580ed5f0175fa98faec8fce772
SHA3-384 hash: 639fab2db0ccc6170417ebac77665533d7b9b243ac34249f0554f2d037894f4a31b45a60535a67c0c30a40eed593ccd8
SHA1 hash: 4b3cbb43e06c655624a3456354c9adef11563a2f
MD5 hash: fab698bf508f82b2a136bc54c1ded412
humanhash: ink-chicken-wolfram-lamp
File name:new request for quote.zip
Download: download sample
Signature GuLoader
File size:76'232 bytes
First seen:2020-06-04 06:04:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:bxP9swiE0gODmFabT203u/Cg8v5b+JsIufvE87ZMhQh/KlbJXlWHp1:bxP9skOoabq0e6RYCLFeQVbn
TLSH 1173121CE16337468AAEE0ACFD55EFB6A29B3FF18DB9CB700F10949530D1405B836591
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.huttprimax.partners
Sending IP: 162.241.215.47
From: Zahira Sughra - petronas <Zahira.zarinudrin@petronas.com>
Reply-To: Petronas Malaysia <petronas@representative.com>
Subject: Fw: New Request for Quotations
Attachment: new request for quote.zip (contains "new request for quote.exe")

GuLoader payload URL:
http://jumapatagonia.com.ar/donmaster/bindonmaster_XDaSW184.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 13:18:19 UTC
AV detection:
23 of 31 (74.19%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip df4d24a276ca00cd58a53bb275f6e5344cf223580ed5f0175fa98faec8fce772

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments