MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 236ec699e5fc1e4d66c8adf9825326df8313f54b97e01416b21bcac5d32255dc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 236ec699e5fc1e4d66c8adf9825326df8313f54b97e01416b21bcac5d32255dc
SHA3-384 hash: 84f8aec7cb91a75b25a8ff43d1a0733a9d981798435655ca2ed287f6d5001508750619d90dfb8eb25f0e9e86d4597e03
SHA1 hash: 5f12189eadf770a08c527888eae392e45252971a
MD5 hash: 100a4e879e897322cf2799d82d1fcab6
humanhash: hamper-spring-hawaii-thirteen
File name:Order CVD-7104618_pdf.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-04 17:21:39 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:5M8DrdLtwkVc0qTAowDwvU2ESTrHsSNr06QQDWuAm:5xrdhDVpqTCEwST3C+6m
TLSH 5645D607B90DC78EE2048AB1F97252F40A79AF1BE4415D2BFACCFE1DB6B024C24555E9
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: fastmail.com
Sending IP: 172.241.27.139
From: Nancy Anderson <dannysanders222@fastmail.com>
Reply-To: dannysanders222@fastmail.com
Subject: Order Receipt CVD-7104618
Attachment: Order CVD-7104618_pdf.img (contains "Order CVD-7104618_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1SRYKGO5xpgYZAxKdiSGlMnssBLKY3VcQ

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 17:36:05 UTC
AV detection:
11 of 31 (35.48%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 236ec699e5fc1e4d66c8adf9825326df8313f54b97e01416b21bcac5d32255dc

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments