MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14f4c8800634baa021417d2dd00661a044487d711140dead81bb5d359aa60fba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 14f4c8800634baa021417d2dd00661a044487d711140dead81bb5d359aa60fba
SHA3-384 hash: d01a01baf7272d5401d0cdcf4ad05caf68d66cee4baee3765b5b414dd4ac4751959d0296e8792cdda5532c9a7ea720b5
SHA1 hash: dc05ab77a90eb5d03202505c5b59a4021d5175f9
MD5 hash: ad49b4e8f455609d2053bbd5a7100b89
humanhash: magnesium-coffee-carpet-tennessee
File name:JAN_QUOTATION_RFQ38787_A_Bich_Thien_Trading_Co_Ltd.arj
Download: download sample
Signature GuLoader
File size:29'465 bytes
First seen:2021-01-11 08:18:04 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 768:UwhVPNYpwf2huE8NBb5SyeN/9hU5/Jz+m:vhBNYpbaBb5w/9S5/JzJ
TLSH 67D2E0FE8712121B6AA3AEFD2D95EF30208066D173F70D47324AF7B87D062990767614
Reporter abuse_ch
Tags:arj GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: hole.com
Sending IP: 51.79.143.118
From: Nhung Do (Ms) <info.nhung@valentinozo.ga>
Subject: QUOTATION RFQ#38787-A
Attachment: JAN_QUOTATION_RFQ38787_A_Bich_Thien_Trading_Co_Ltd.arj (contains "JAN_QUOTATION_RFQ#38787_A_Bich_Thien_Trading_Co_Ltd.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=A951308400164DD4&resid=A951308400164DD4%21106&authkey=APE43C5aWsOop18

Intelligence


File Origin
# of uploads :
1
# of downloads :
149
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

arj 14f4c8800634baa021417d2dd00661a044487d711140dead81bb5d359aa60fba

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments