MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fa961ae88943face987125844e588340791281857d098838772f21560e6dbaa8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fa961ae88943face987125844e588340791281857d098838772f21560e6dbaa8
SHA3-384 hash: c393ac1beb21b13be14828acaf63273f97f350b1093c19e1a2e5e786786954ea6a83dc7b926dca4e50984b0e13639e07
SHA1 hash: f2e52f325e5e93e9e38eeea233c71d13fe6dd9f9
MD5 hash: 05193eed0330fb031081aab4183c5332
humanhash: hydrogen-nitrogen-papa-hot
File name:quote008976-21-2020.iso
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-21 08:44:24 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 768:cKcw54hfWT+zCfFpI8smr0zeoiyuc34sGSsFoH9uTPuF6:B4hOT3Cmr0ze/Dc3jGSscuTPuY
TLSH 3E454B11F585DC62C4588AFE4FA2C614513FAD340861CB4B7EDD3B0D2BFA992A83578B
Reporter abuse_ch
Tags:GuLoader iso


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: longerinc.com
Sending IP: 160.20.147.182
From: serena<serena@longerinc.com>
Subject: quote
Attachment: quote008976-21-2020.iso (contains "quote008976-21-2020.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=46B98FE6F0D79519&resid=46B98FE6F0D79519%211842&authkey=ANcfRm-0LjxFJQY

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 09:36:48 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso fa961ae88943face987125844e588340791281857d098838772f21560e6dbaa8

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments