MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 194703f48f54a9ea92e9ba5fcad828ef03f6e9be283b18a2ce22aaaf2d76645f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 194703f48f54a9ea92e9ba5fcad828ef03f6e9be283b18a2ce22aaaf2d76645f
SHA3-384 hash: 4d6df714d6dcf1c06f769e063a01624d2bdb363daafdcdf51f2d5711c6e951b91e1da3010327db9e28741a1e64fc2211
SHA1 hash: a04b64f5d59665d3870f06719122d01eabd317ee
MD5 hash: 0570c89916bec612382b0d0c61572a65
humanhash: delaware-football-asparagus-michigan
File name:Proforma Invoice 450MT 5 Mei 2020.zip
Download: download sample
Signature GuLoader
File size:31'751 bytes
First seen:2020-06-10 06:48:12 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:QMtR1Ze5BfB1VZpPF+gZpHBIncx+73OF9ci2AJ9pypgA:QeR1IjB1tPFFSncxm+bcT09MP
TLSH 12E2E10ED6D60475E4928751182A9259E709EE32F7F130DC3BAB5E2EB6763F011EA138
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: host130.cityonlinebd.net
Sending IP: 113.212.108.130
From: mary.jane@rnz-group.com
Subject: Order Acknowledgment No 1655235
Attachment: Proforma Invoice 450MT 5 Mei 2020.zip (contains "Proforma Invoice 450MT 5 Mei 2020.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1oOaHXu7l0pl8Fn9fbk7qrTqqVg7SWli3

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-10 06:50:07 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 194703f48f54a9ea92e9ba5fcad828ef03f6e9be283b18a2ce22aaaf2d76645f

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments