MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 214ff293158223d64726e3ade2accf7fde041923afa2dc8a2723b5a54e0b8f97. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 214ff293158223d64726e3ade2accf7fde041923afa2dc8a2723b5a54e0b8f97
SHA3-384 hash: b20cb74a466db8101ab3c232bd46baa97de7f9d97e43b8662cbe4e888d3cc9ab09662f7af4060a69ad0bbca7d8791b95
SHA1 hash: 47d2e7fd3554d9c7653ead5135c74d8e5451b226
MD5 hash: 8164bd60c71956772619896270885c2a
humanhash: july-speaker-robin-floor
File name:invoice copy.zip
Download: download sample
Signature GuLoader
File size:45'464 bytes
First seen:2020-06-08 12:04:51 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:64od4MH81TAdxZ12tmBmnPrVxCLxMaOT70VgbIea4NEz6SLCeY:6pf81Ed8tmBqPJQtMnbIdXj+eY
TLSH 8B13F162093A7980A2CB4AFF6BC5024DD34D2D936893E934BADF54E45FDCB788528E14
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: [156.96.60.4]
Sending IP: 156.96.60.4
From: hcshin@shinpungtex.co.kr
Subject: invoice
Attachment: invoice copy.zip (contains "invoice copy.exe")

GuLoader payload URL:
http://156.96.118.179/BELIKE_xEIfjzYvQm206.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Spyware.FormBook
Status:
Malicious
First seen:
2020-06-08 12:06:07 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 214ff293158223d64726e3ade2accf7fde041923afa2dc8a2723b5a54e0b8f97

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments