MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 089ba205a3966767a087d8356926cb2ba4c7cde4c4dbfc84da165283cba38076. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 089ba205a3966767a087d8356926cb2ba4c7cde4c4dbfc84da165283cba38076
SHA3-384 hash: d5ff38f91fcec550cfdef7cea90ea01ca3ee5098f587a65e2e5b0347ff09397fcf3c31fb2dab533ac223b2c1d904cae5
SHA1 hash: 18f13b1baa126b14481c0b2e90fa05dc3d7d61e3
MD5 hash: 46791007543e567814d8467b30e56c60
humanhash: alabama-ink-crazy-march
File name:HSBC Payment Advice.iso
Download: download sample
Signature GuLoader
File size:25'176 bytes
First seen:2020-05-21 10:26:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:0psgTgDUbrRGxbnXu8BmJcOBcMOZvogaSU8mBkYRD+Zb7iq5b2L/vTCwg5cL:qTTgYPRGV+8BbOOZO8mXDab7iASjrCbm
TLSH E6B2E168F58D3553CFD178935A5929C0E61EE2F83CD41EB839D8B054EA83328C98ED25
Reporter abuse_ch
Tags:GuLoader HSBC iso


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.katherinefashions-inc.com
Sending IP: 65.75.147.158
From: HSBC Advising Service <info@hsbc.com>
Subject: Payment Advice - Ref: [HSBC105702520] / Priority payment / Customer Ref:[PI1007057QT20]
Attachment: HSBC Payment Advice.iso (contains "HSBC Payment Advice.bat")

GuLoader payload URL:
http://www.mailserverservices.info/bin_hEJPi68.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 10:36:43 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 089ba205a3966767a087d8356926cb2ba4c7cde4c4dbfc84da165283cba38076

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments