MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2902bd3eb245fa752a2cc29d98177c8d627f9fbdf0904a7ab58279ae7a6ba22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f2902bd3eb245fa752a2cc29d98177c8d627f9fbdf0904a7ab58279ae7a6ba22
SHA3-384 hash: ece4a4dfa1f4f67c1f17823637b7efc91c29104510f548fffb0868f4005a4eb76db7677760db26507c48a994350837ee
SHA1 hash: 23494f9f34eb9c1f99c3657d7bbe1eeb6200b079
MD5 hash: a2d03647bdc78b5bc5a4e53c9331bbad
humanhash: pasta-west-massachusetts-nebraska
File name:file.zip
Download: download sample
Signature GuLoader
File size:88'488 bytes
First seen:2020-06-04 15:51:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:tEbAHDVtIn6k/CU+iGuFs6rtqnVwFyaa83jYtgY+hn5dnii4+JF1tSI1rMmnIK6F:AAHD/I6k/qt0s6rQnVKauxYAnDnpf2IM
TLSH 7783121CBBA3F4C664C2D6188FB0BA1A44D5D3421C9AF581E0A3C15ACDF85C6A5D79E3
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: slot0.northern-safe.com
Sending IP: 45.95.169.178
From: Nicole Gapes<info@northern-safe.com>
Reply-To: gapes.nicole@yahoo.com
Subject: Property Purchase & Leasing
Attachment: file.zip (contains "file.exe")

GuLoader payload URL:
https://rainbowisp.info/dot/js/piro.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 16:27:05 UTC
AV detection:
6 of 31 (19.35%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f2902bd3eb245fa752a2cc29d98177c8d627f9fbdf0904a7ab58279ae7a6ba22

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments