MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 27a5b4ce3099ff85cee78bdd4fbb6faf90bcced1e250d8b52ab578feb3b26547. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 27a5b4ce3099ff85cee78bdd4fbb6faf90bcced1e250d8b52ab578feb3b26547
SHA3-384 hash: c3357555a9b2b1624c5c60a2c5f82973397fed40cefb9cda970c4c23214fd0759460ca52118384bff1ae737a51a24c48
SHA1 hash: 4205a3466f3ded243edc14aa0545d4e26fc81bbc
MD5 hash: ab172483e0c957a8eada76c05e006a1f
humanhash: comet-football-vermont-edward
File name:Order sheet_Product Prices list.rar
Download: download sample
Signature GuLoader
File size:41'270 bytes
First seen:2020-06-09 06:29:39 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:EY6LK+r9Ft7e46ccCn4vzXz6yojzJ0IwGhHnuevU1SBN:YLKcoscCIzXGyonJ0ItFnuIUABN
TLSH FB03F1278B45506A979903E3CAA30A9B116EDD0852216FEAB8315C67514F3DBF71F80B
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

From: Eva Ssonko Baliraine <eva@cdrn.or.ug>
Subject: New Order 09-06-20
Attachment: Order sheet_Product Prices list.rar (contains "Order sheet_Product Prices list.bat")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1FH6LQldmev8rtFzAZ7mI3hYN1hPVTCSf

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-09 06:30:12 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 27a5b4ce3099ff85cee78bdd4fbb6faf90bcced1e250d8b52ab578feb3b26547

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments