MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e2bfc878c24b0c81c5f22af8f54eae1fa4abf218840861ecd293e79e50131291. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e2bfc878c24b0c81c5f22af8f54eae1fa4abf218840861ecd293e79e50131291
SHA3-384 hash: dfbe146ef1b3f862909eb441a5a239030908ef6d123fc47d84c2c59680773b4c39b91fce6674a508b6da92cc3a1e93f4
SHA1 hash: 9c67047e79b10c55c94194289fec8cf2af777a2f
MD5 hash: 4bc0419575a3b08e02515e55ce1a7918
humanhash: utah-violet-two-wisconsin
File name:Maersk KPR_Draft_Bill_of_Lading.rar
Download: download sample
Signature GuLoader
File size:44'007 bytes
First seen:2020-06-08 05:30:15 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:z51bm/Lhvu/s9GzmOswG2/WJmJuoEEQv8DxEjLt+lBvf:zjm/LhvUFiw7eJmJuoEEWLHtavf
TLSH DA13F116AB7F75834FC9B2320D0359A441178E15F24D8DC256917BBAF46EAA7E303D4C
Reporter abuse_ch
Tags:FormBook GuLoader Maersk rar WeTransfer


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: sta.staunchvaluededicated.com
Sending IP: 162.214.70.141
From: WeTransfer <usetolif@jsrnana.com>
Reply-To: WeTransfer <usetolif@jsrnana.com>
Subject: Maersk KPR_Draft_Bill_of_Lading PO_1218103#XML_36425762
Attachment: Maersk KPR_Draft_Bill_of_Lading.rar (contains "Maersk KPR_Draft_Bill_of_Lading.exe")

GuLoader payload URL:
http://ratamodu.ga/~zadmin/group/sen_AIYKO236.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 05:32:04 UTC
AV detection:
17 of 29 (58.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar e2bfc878c24b0c81c5f22af8f54eae1fa4abf218840861ecd293e79e50131291

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments