MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e837a59ca55bed0f8ee116f2d2986d4856fa080c8bb0b057a15f3ca166b2e4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 0e837a59ca55bed0f8ee116f2d2986d4856fa080c8bb0b057a15f3ca166b2e4c
SHA3-384 hash: b39c21173628ad77e03dae58ab768215301f01fd097c6168b540afd913260285f11aece3c77e1bb6767edc7f20aa8d16
SHA1 hash: 97ae936f7d87c6732e0b64cde990392130ec7674
MD5 hash: 88a3a7504ab2b0ecfd4d7a9dd99012fb
humanhash: hotel-emma-quiet-floor
File name:CEMENTOS-DOC.rar
Download: download sample
Signature GuLoader
File size:20'293 bytes
First seen:2020-05-27 17:13:17 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:3yHXsPERmaWEt/RYQF0r9F5z4CDlnB+/CzMMnkkuKAS2nDdu1FY:QXsPERwER0r3+CDlB+/CzMMnkrlZ
TLSH E792E157308AB5E4914DDEB439D50BBE1510C1AEF8B25A1F8326AA337C5A02365CACCB
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: yisun.co
Sending IP: 111.90.159.196
From: JUAN ALBERTO URBANO <grencia@cementoscauca.com.co>
Reply-To: hinduhyog2011@gmail.com
Subject: QUOTATION INQUIRY
Attachment: CEMENTOS-DOC.rar (contains "CEMENTOS-DOC.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1mHIDpQjHwculBfbm0z1U-xm73_DIRaRl

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-27 17:36:34 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 0e837a59ca55bed0f8ee116f2d2986d4856fa080c8bb0b057a15f3ca166b2e4c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments