MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13608ad3ca7c746d9ba19de8fd96ac3da5a2138c9945dc44691be7732c4632f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 13608ad3ca7c746d9ba19de8fd96ac3da5a2138c9945dc44691be7732c4632f8
SHA3-384 hash: 1d64c25c7f73ea9db9b40e76720cb7e5d896040f0562785c736e0f9f9c6650972be3fd5670056ba59b89a91a4282fa4f
SHA1 hash: 955a760c4e8684cc13f300bcee349ee940a9eb41
MD5 hash: a9b32d8e29b890f035724c96698ca835
humanhash: maryland-quebec-tennis-fish
File name:FedexAWBinvoice2410202.img
Download: download sample
Signature GuLoader
File size:110'592 bytes
First seen:2020-10-26 13:41:13 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:ip1pJ2w1qi/G7CMQTNkI34LT4I5hwO+b:vZ8xMWZO/O
TLSH 30B328DF6345C4AEFDA14F71BE45B6AB62337F290A17890F368C7A181F72700A801E16
Reporter abuse_ch
Tags:FedEx GuLoader HostGator img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: gateway23.websitewelcome.com
Sending IP: 192.185.49.104
From: Fedex@Fedex.com <Fedexshipping@Fedexexpress.com>
Reply-To: Fedex@Fedex.com
Subject: FedEx Express AWB#5305323204643 - Information is required
Attachment: FedexAWBinvoice2410202.img (contains "Menstruosity2.exe")

GuLoader payload URL:
https://simplesolutionsdivorcemediation.com/2_nRpYI120.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Graftor
Status:
Suspicious
First seen:
2020-10-26 02:07:41 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 13608ad3ca7c746d9ba19de8fd96ac3da5a2138c9945dc44691be7732c4632f8

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments