MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16bc39745a2cf70fd35fd05a13cad3d0cb537c60b42184f45c591ddffc0b8396. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 16bc39745a2cf70fd35fd05a13cad3d0cb537c60b42184f45c591ddffc0b8396
SHA3-384 hash: fa095c045b5b219627081cc2e66b55abadfb80904202dba451176bb68710993c434179e8799442a9b76eacacb487019f
SHA1 hash: 271b435c39572a88bf52f0e4da24de8473c309be
MD5 hash: 0e60fd664919659838a4241a87e3e975
humanhash: jersey-tennis-idaho-charlie
File name:PROFORMA CONFIRMATION.gz
Download: download sample
Signature GuLoader
File size:41'650 bytes
First seen:2020-06-09 06:35:31 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:ZBaPtjKZEHFB5YH6r+WvV+IkLZi5hAwKjGPsRvDW7lr4qWYtA3zx72JCyxx+w:ZBa1+EP5MrYVLkNiLdgCBLtA3F7axl
TLSH F413F12AB1D11A224F0870A83A406B2E46454F97DBF519ED6A37F0CC3EA19FE1563C5F
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: hos7.host4asia.com
Sending IP: 158.106.138.106
From: Ms Williams <williamsonms@netvigator.com>
Subject: DOMICILLIATION OF USD PAYMENT /ACCOUNT DETAILS VERIFICATION
Attachment: PROFORMA CONFIRMATION.gz (contains "Sc08 ACC CONFIRMATION.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1gZZI0STZ-QLcUS09Fxgk8XPWJz0z4upU

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-09 02:52:47 UTC
AV detection:
32 of 48 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 16bc39745a2cf70fd35fd05a13cad3d0cb537c60b42184f45c591ddffc0b8396

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments