MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 239094ed3739b40d61b0a30f4e033d1575f77813e99cf1ecc3368e4e327d8542. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 239094ed3739b40d61b0a30f4e033d1575f77813e99cf1ecc3368e4e327d8542
SHA3-384 hash: 9f78c9b3f62d0542119c9c0298c998c106c187f68ec3b072ecb025bea81fb84f6b57025a6fa7b3ec03c08f6805623e8f
SHA1 hash: ebac36235a8e5ef51613b09ac84a92bc4dbc2c41
MD5 hash: f4e4537ed5cfe97fe936dbf23bd84542
humanhash: louisiana-blue-maine-rugby
File name:DHL AWB.gz
Download: download sample
Signature GuLoader
File size:46'924 bytes
First seen:2020-06-08 12:13:48 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 768:aFTSTCkn7xYeBG1Zgit4v+vI0rNAW2DmyO65vOGs4Ug73neZ8c6JrkwXiTkdtxGs:kGT/76uGPgiev8IAAW2DJO65vOGGgzh9
TLSH C423021CEE5ACE1D3F19DE09D533D9E99A8D5C899482C4FE589340C3BAC8D13F86D144
Reporter abuse_ch
Tags:DHL GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: slot0.cn-nakareg.com
Sending IP: 45.95.169.32
From: "DHL EXPRESS" <info@cn-nakareg.com>
Subject: DHL BILL OF LADING SHIPPING DELIVERY NOTICE
Attachment: DHL AWB.gz (contains "DHL AWB.exe")

GuLoader payload URL:
http://baritaco.com/build_VSJicTAg206.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-08 12:15:06 UTC
AV detection:
29 of 48 (60.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 239094ed3739b40d61b0a30f4e033d1575f77813e99cf1ecc3368e4e327d8542

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments