MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20a4c0bf806db309991c469fc52c5d1a3cc16b18d139bea50a9f3b2710762407. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 20a4c0bf806db309991c469fc52c5d1a3cc16b18d139bea50a9f3b2710762407
SHA3-384 hash: 58bde010912a2a2921261010d817ce441914e1d2993f4b90415c0215787a7d14b8672d6580726d85cc49ec90e21e6979
SHA1 hash: 68a7312970e194fb77223c955db20e4c9783cc4e
MD5 hash: 4dd53bb079f87abc289f8a6c515d9886
humanhash: paris-west-louisiana-social
File name:HYUNDAI MASS QUARANTREAT PROJECT.dwg.cab
Download: download sample
Signature GuLoader
File size:41'159 bytes
First seen:2020-06-02 10:59:00 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 768:6fXJOMnIRMXDT7fAa1ZnDuMmst3BmaVeXdwG1pMuLtEmEmgQ:mkMIWXfzAa1VD3t3BmbdwG11KZq
TLSH 5703F187632AC0EEC3167D21BC784854DDD648D51F8BB68286A3031F266B45A3ECF778
Reporter abuse_ch
Tags:cab geo GuLoader KOR


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm44.hanmail.net
Sending IP: 203.133.180.232
From: 로이 유 <farmsco@daum.net>
Subject: 견적요청의 件:HYUNDAI MASS QUARANTREAT PROJECT
Attachment: HYUNDAI MASS QUARANTREAT PROJECT.dwg.cab (contains "list.dwg.exe")

GuLoader payload URL:
http://ekenefb34logs.webredirect.org/uploud/5bab0b1d864615bab0b1d864b3/smik_DmaNZPfC106.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-02 06:58:09 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

cab 20a4c0bf806db309991c469fc52c5d1a3cc16b18d139bea50a9f3b2710762407

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments