MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 127fc371c113ace11806523a450ac593ca259d590ce3e6219b41d6befc7e9c98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 127fc371c113ace11806523a450ac593ca259d590ce3e6219b41d6befc7e9c98
SHA3-384 hash: d2963bd7b591b48be888be74bee81059f0a65fc13ebe56c66c0db786f59fb27b3240653a93fd56717edd236a422bddee
SHA1 hash: 0bac57b1f7cc6f02072307cbd0a99c87df274e99
MD5 hash: b3fafa25a807d509de327515df024402
humanhash: equal-kansas-alaska-don
File name:PO Attached.gz
Download: download sample
Signature GuLoader
File size:30'048 bytes
First seen:2020-10-26 14:31:51 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 768:VA0kLHsHjvMxqkJB/1YfV9Am62bDB03ux5FaRd8:+tMvMUGV2vAm6U03u0T8
TLSH 0ED2E1E6F12FC9C5E0000FA3A7E3B9680872853054C9C65DDB3969A59DD76913C3A7B4
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: whm.dhakacom.com
Sending IP: 202.4.96.47
From: info@bhawalresort.com
Subject: Fwd: RE: New PO
Attachment: PO Attached.gz (contains "PO Attached.exe")

GuLoader payload URL:
https://redesuperpops.com.br/kalidoc/CEE%20JAY%20ORIGIN%20FILE_IlZpJ111.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
150
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-10-26 06:57:44 UTC
AV detection:
15 of 29 (51.72%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 127fc371c113ace11806523a450ac593ca259d590ce3e6219b41d6befc7e9c98

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments