MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f1670d48f2547e3f47b8eaa7e096d1d67aa09d5f80a51d97c737e36e50cd99f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0f1670d48f2547e3f47b8eaa7e096d1d67aa09d5f80a51d97c737e36e50cd99f
SHA3-384 hash: 1c04bdaa1d80ab565a8d740975e5aa1a7c1c5742f00bf086e64eef367ad600d78eb28fd4fe62d9c67ec4a1558500b5e9
SHA1 hash: ccc2a3589945109effeabe20068b08903d681cd9
MD5 hash: 539127258e36a545d432e74f77f4cd74
humanhash: princess-paris-johnny-uranus
File name:scan1169 SWIFT COPY.DOC.zip
Download: download sample
Signature GuLoader
File size:76'614 bytes
First seen:2020-06-03 13:29:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:mys3Uq7T8PbVBKxY7IkXE4X8WtSr4oqWZddis2sA9:mD1mm94Xsr1Zddis2j9
TLSH 6073021FFFBF83638E875CBE50C270446246DDF5D4B8040408DB59036BAEB72EA92666
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: host130.cityonlinebd.net
Sending IP: 113.212.108.130
From: Andrew Sommerville <andrews@gbj-ltd.co.uk>
Reply-To: drivee457@gmail.com
Subject: Re: RE: ENCLOSED SWIFT COPY PAID
Attachment: scan1169 SWIFT COPY.DOC.zip (contains "scan1169 SWIFT COPY.DOC.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1cst2lo44fPOBNX8uRFwHc-KZ6UzF20oX

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-03 13:37:20 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 0f1670d48f2547e3f47b8eaa7e096d1d67aa09d5f80a51d97c737e36e50cd99f

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments