MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 18e55a038560fcf952ddefa19902d91cbc728283e4738ebb6224b58733a486ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 18e55a038560fcf952ddefa19902d91cbc728283e4738ebb6224b58733a486ca
SHA3-384 hash: 6e676de9e2adea6b6612be15ec4261487108a5a7f04b7662360b56a731aa8abdb4842c0d8c5499aeae7a2570caf12ff3
SHA1 hash: 73ace9d60c47ff058f507a629511f829346a6f2f
MD5 hash: 5501273b82f06964518b70e06dabb842
humanhash: fillet-november-july-pip
File name:XIU SHAN - DOCS_00038450_062020_pdf.gz
Download: download sample
Signature GuLoader
File size:45'556 bytes
First seen:2020-06-08 12:05:06 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:rkmo+ubdSMDUCPZW3KdhyZk7ibWBgt06u0x1fVcg/rZI1Iq2x537:rRo+CfDtZPdUZk7cMg66u0xNVcg/1Cob
TLSH 5513F16140D3F995EE58409036BCA6C5F5F3AE980A7F7B6A1BCA3A2105C9DC9E4220C7
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.basungaintl.gq
Sending IP: 91.132.139.205
From: limkim@nitto-ntl.co.jp
Subject: MV XIU SHAN supplied Japan 19.4.20
Attachment: XIU SHAN - DOCS_00038450_062020_pdf.gz (contains "XIU SHAN - DOCS_00038450_062020_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1Dh4NjabxYgQU1YG0LtW3DfI_78Sef46q

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-08 12:07:04 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 18e55a038560fcf952ddefa19902d91cbc728283e4738ebb6224b58733a486ca

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments