MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12dcddc725d63958436e513bf353b784ef487d647af7cc92353783deb33f8113. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 12dcddc725d63958436e513bf353b784ef487d647af7cc92353783deb33f8113
SHA3-384 hash: 8a25c9683a84b72fe596ddec9c76d0b3315c849a73e3f81ca5057b41b60e3c14920493e7f956abfa0ddfbc940d77ee07
SHA1 hash: 0e579567f6e3a14b77c9eadfcefe397a756b4dae
MD5 hash: 16799c718ee24d39bfc1e0837ef86d99
humanhash: fish-steak-july-failed
File name:20200424_PO1757611yk.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-07 06:41:39 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:ZZ/J+BWO/mK1/YIH3rykAP4kNGnI5Bb6HhO7CMsIVdNQSNBH:ZS/mBM7yXP4kNbvbOWV
TLSH 3C45A4116EB4EE2AD25436B0DBA5F6AEC365BC3026324D0734CD3A1A2F35E568C7125F
Reporter abuse_ch
Tags:geo GuLoader img KOR


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm38.hanmail.net
Sending IP: 203.133.180.226
From: 씨맥스광주 <hana5744@hanmail.net>
Subject: 견적의뢰드립니다 - 씨드코
Attachment: 20200424_PO1757611yk.img (contains "20200424_PO1757611yk.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-07 13:34:50 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 12dcddc725d63958436e513bf353b784ef487d647af7cc92353783deb33f8113

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments