MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2090ef501bf30eff58e65ff4491b5a913e5e105ff952b6d26b3e5ccf9e251cc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 1 File information 4 Yara Comments

SHA256 hash: 2090ef501bf30eff58e65ff4491b5a913e5e105ff952b6d26b3e5ccf9e251cc9
SHA1 hash: ac2de01753ac3d0eaafc7e05eddbc0db7cf6ae21
MD5 hash: 19441c079bebced94897c9dcd3567d99
File name:file.exe
Download: download sample
Signature GuLoader
File size:90'112 bytes
First seen:2020-05-22 09:49:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0dc990cfa181d27f4e5295fa5b773658
ssdeep 768:fQweoPOoz1XMLqiI78nr+YSaf5qjpCLg2UFT1dsRtfZEoo8mh:oweA19is8r+hs5epag2wOCoyh
TLSH 89932A017664DCA6DA4049F2CE274BD40EABAD706E014F0B34C9BE1C2A33D877D2C69B
Reporter @abuse_ch
Tags:exe geo GuLoader KOR

Malspam distributing GuLoader:

Sending IP:
From: UTITECH <>
Subject: 유티아이테크-발주서 송부의건
Attachment: file.lzh (contains "file.exe")

GuLoader payload URL:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 21
Origin country US US
ClamAV No detection
VirusTotal:Virustotal results 42.25%
ReversingLabs :No data

File information

The table below shows additional information about this malware sample such as delivery method and external references.



Executable exe 2090ef501bf30eff58e65ff4491b5a913e5e105ff952b6d26b3e5ccf9e251cc9

(this sample)

Delivery method
Distributed via e-mail attachment