MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a2569290a1c172bf7825de4cb545ce4490fb1e21cc9488f002d31ef314f3fe2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a2569290a1c172bf7825de4cb545ce4490fb1e21cc9488f002d31ef314f3fe2
SHA3-384 hash: ed8f4c29ea22fe583d289107db57bebef434617fa8e08a8fcf499d9d6a85c19219218c8a6aefc738ff271e85b0b13676
SHA1 hash: 72f497032624a64a93ac3662792e66a9070caf3b
MD5 hash: af1fb980aaa27f9fbdd7619d49355226
humanhash: finch-venus-april-friend
File name:SOA PNC_zip.arj
Download: download sample
Signature GuLoader
File size:74'001 bytes
First seen:2020-06-03 13:04:04 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:477/YxKmJ4d6Qq1kewk/xTiyPV40oQoIoxM14t5:4773dpI/JPV/am1O
TLSH 2C73019C7B620D3FC87ACD95A9875E1E1B54830BC02A6B29569CD53816BF80B3678F40
Reporter abuse_ch
Tags:arj GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.gegcc.com
Sending IP: 192.64.78.30
From: tariq@gegcc.com
Subject: Fwd: SOA - Oustanding Balance Payment Schedule
Attachment: SOA PNC_zip.arj (contains "SOA PNC_pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-04 04:29:30 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 0a2569290a1c172bf7825de4cb545ce4490fb1e21cc9488f002d31ef314f3fe2

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments