MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 118b2e8ad335835fc74d58f08b18196ea3f1fd112446406814f49e9a0c30df30. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 118b2e8ad335835fc74d58f08b18196ea3f1fd112446406814f49e9a0c30df30
SHA3-384 hash: 56bdc4a1d8bf6f535b7cfba3c785996028adf17505bc9b288cc49341557b924e4f314ce534e55e14948a25fbd5950315
SHA1 hash: 61433544998d58673e4af95133d2a77bd6e19631
MD5 hash: 67970e17260037c682c8dc35a310296f
humanhash: alpha-single-white-earth
File name:SWIFT.zip
Download: download sample
Signature GuLoader
File size:33'747 bytes
First seen:2020-06-10 17:29:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:8ytSUINBel0BetgAW+NcoUHlzUVhVJJv9hrrpNx6iI5u1nv:8ytBINBg0BetgyyrzUxvhIYnv
TLSH B3E2E169C32762F2E1CA5709F727502229825A83167683317E8CCEE5A5F0D6561DBA3C
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

From: "Amy Li - Account Payable Addcon Asia Ltd." <contact@bbconstruction.online>
Reply-To: "Amy Li - Account Payable Addcon Asia Ltd." <ann956844@gmail.com>
Subject: RE:Account Statement/vbspamtest.com
Attachment: SWIFT.zip (contains "Canzonenng8.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1M-ObtJKVduN5fpVgXp10StT50xuD8fzK

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-10 17:30:17 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 118b2e8ad335835fc74d58f08b18196ea3f1fd112446406814f49e9a0c30df30

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments