MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1dc020a18521f163738c27487393fc4825e0bbeadf858318f45d57e764034b9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 1dc020a18521f163738c27487393fc4825e0bbeadf858318f45d57e764034b9c
SHA3-384 hash: 1c2dfdd4520b5e3e51e1d195ea89a65b2b47cf610ea72db546c783213150ea984638be864970e7f4fe3d123231e880d2
SHA1 hash: 44bcf43c926993ebe2390036e83c06e1d85543e1
MD5 hash: a029e9690fd9d53a77607c75afb977a5
humanhash: jig-shade-golf-oven
File name:PO.rar
Download: download sample
Signature GuLoader
File size:53'494 bytes
First seen:2020-05-28 13:17:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:brO/e6m1RmQIYHdggdrwQuAfcxzzZwidKPjxjsDgEG:b6W6IJpdggnLyPGIgX
TLSH 8733F1DCF399EA8B0627F9B8533D0F2A17CE63775402785BA9E056EC61270F47045D2A
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: 134-0-117-239.ovz.vps.regruhosting.ru
Sending IP: 134.0.117.239
From: Rafal Gasior <dsm.mahmudul@athaque.com>
Subject: Orden de compra 2003161-0 #NUEVO STOCK
Attachment: PO.rar (contains "PO.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1Luq-19sOnMgZ8ZZ2Jq05a8M8oOBPwKj-

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-28 13:37:20 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 1dc020a18521f163738c27487393fc4825e0bbeadf858318f45d57e764034b9c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments