MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 026d3b61c94673a39d6b8a936f0fde107c0b9241da3940e8aeea070cad93f19d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 026d3b61c94673a39d6b8a936f0fde107c0b9241da3940e8aeea070cad93f19d
SHA3-384 hash: a3d8b084bc661584cddc72e4866b8582438edf7058e8bcc4f3493b7fde5db3aa1a716b618275d27ad55bf5e2b4511e24
SHA1 hash: 70cf00805fffdb7c0674fbd9473889238c1abb87
MD5 hash: 30d4ecf954465360216a29c84fa9d895
humanhash: jig-failed-violet-butter
File name:Purchasing RFQ_6000116413 PR_0010036518,001003651.gz
Download: download sample
Signature GuLoader
File size:73'126 bytes
First seen:2020-06-03 13:32:52 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 1536:Bbm4L9406DJorYVk0echSvHdbiHQgZVJ6un+7n2C1Si:QG94nyridIQ9nn+6Vi
TLSH F86302B598D0A31218373B2093A43C09FCDB727B5A4409F4F8848AA5C6B15B37E267DE
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: shbc10.ultina.jp
Sending IP: 218.40.207.10
From: Saleh Nafe Al Sayah <saleh.alsayah@nomac.com>
Reply-To: saleh.alsayah@nomac.com
Subject: Purchasing RFQ_6000116413 PR_(0010036518,001003651
Attachment: Purchasing RFQ_6000116413 PR_0010036518,001003651.gz (contains "file.pdf.com")

GuLoader payload URL:
https://onedrive.live.com/download?cid=70C4976FC04DDB54&resid=70C4976FC04DDB54%21115&authkey=AMC_k1nnlYwDC4I

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Razy
Status:
Malicious
First seen:
2020-06-03 13:37:17 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 026d3b61c94673a39d6b8a936f0fde107c0b9241da3940e8aeea070cad93f19d

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments