MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12cb2b3094a89495437f27c90a02bc8426b88467f5260eaa3589bb5fca322fd0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 12cb2b3094a89495437f27c90a02bc8426b88467f5260eaa3589bb5fca322fd0
SHA3-384 hash: 44b905bbc49a0f7e0d1c36f4f20a519f0483ce4d746d0772c239219a018c1ff00d228554cb409b023e4e82101edb8295
SHA1 hash: 2e81ce2777b0148eae9dde3f4ff362db48ac52f2
MD5 hash: 3f53f8e758060318cce8fc1a26ec0e73
humanhash: zulu-twelve-artist-hotel
File name:INV20200531RFQ6748.gz
Download: download sample
Signature GuLoader
File size:73'329 bytes
First seen:2020-06-02 16:01:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:olHMQzSUkysPfkRiRI7kaRSwR8ji+gqO72Bn/X2hNCLkAJ5Lj:4n9psPflqkDfji+gD72BnQNCLk6d
TLSH 10630262578576798467787ABEFA14D7C09766F30DB3C70913207FCE0942ABAC8D08D2
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail1.bm-cheap.site
Sending IP: 62.173.139.179
From: "Jennifer R. Lingad" <jlingad@dorniertechnology.com>
Subject: Re:request for PO
Attachment: INV20200531RFQ6748.gz (contains "INV20200531RFQ6748.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1WAGoGMIRBqecNTPBOW4srU7WAVClT1Wp

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-02 16:35:55 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 12cb2b3094a89495437f27c90a02bc8426b88467f5260eaa3589bb5fca322fd0

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments