MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 1 File information 5 Yara Comments

SHA256 hash: 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc
SHA1 hash: b45ae97e89a44f8a0d602b59fba4c17c611e7820
MD5 hash: 0404c11054da08695c4e159e71316e6b
File name:Payment Copy.zip
Download: download sample
Signature GuLoader
File size:27'663 bytes
First seen:2020-05-22 10:20:43 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:Ov+KhNxveZC3De4w9NEOtOYFRTQ7BeIyWX9GarRT:CTveZCTe4wn2mlQQIyWXx5
TLSH D5C2F1CC5130BB53FB119678F11141DBB59C61E11399EBBC9AD51E0676074FB11F8E22
Reporter @abuse_ch
Tags:GuLoader zip


Twitter
@abuse_ch
Malspam distributing GuLoader:

HELO: mx.shi-ig.com
Sending IP: 217.61.123.234
From: jeff@shi-ig.com
Subject: Re:Payment copy
Attachment: Payment Copy.zip (contains "Payment Copy.bat")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1dje1f5MKekSEqm5EHUuqTF-64jLzc6Hn

Intelligence


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 21
Origin country FR FR
ClamAV SecuriteInfo.com.Trojan.DownLoader33.44126.29095.12728.UNOFFICIAL
VirusTotal:Virustotal results 9.38%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 1b7af0fafc23284ae3389bb487d28a9631e72c7677970ea5f48615be5b6548cc

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments