MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2816b4cb7c5d8b87d1d56e855af0a2dba02782b7e6ac375a0ef41e1226147156. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2816b4cb7c5d8b87d1d56e855af0a2dba02782b7e6ac375a0ef41e1226147156
SHA3-384 hash: 95c50087d6132a611d601295a07ea95c1cf878e34a65bef7d8bcea503aedbaf6d8a536c9d021385c485a8aaaeb3ea7a6
SHA1 hash: 1dcbef8bd1d3bc819d8b765d00a20c292eb18f2b
MD5 hash: a95e94aa91e2c6cddbbbc018572ee46b
humanhash: juliet-eighteen-muppet-twenty
File name:Product_Me_Order_Pictures _pdf.zip
Download: download sample
Signature GuLoader
File size:120'844 bytes
First seen:2020-08-19 12:21:25 UTC
Last seen:2020-08-19 12:22:38 UTC
File type: zip
MIME type:application/zip
ssdeep 3072:IvBm+/D+DwpSZcS4tjJgBtFWB3Zr92WApZSbwqwb+r3xMqnK:IvouDhCcS4tCTFiV9pbzrm0K
TLSH 32C312F97EFEE0A5E66F31E60061948FF9D0E609F2A4C2139D095D04666A3C44B72C3A
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: slot0.ricksaezp.com
Sending IP: 104.168.173.112
From: info@ricksaezp.com
Reply-To: info@ricksaezp.com
Subject: ATTACHED FILE PRODUCTS NEEDED PLEASE
Attachment: Product_Me_Order_Pictures _pdf.zip (contains "Designs jpg jpg jpg jpg.scr")

GuLoader payload URL:
https://onedrive.live.com/download?cid=5624EA93AB8BAD8E&resid=5624EA93AB8BAD8E%21139&authkey=AHZF3gFTm8oMJ7o

Intelligence


File Origin
# of uploads :
4
# of downloads :
231
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-08-18 14:30:56 UTC
AV detection:
19 of 48 (39.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 2816b4cb7c5d8b87d1d56e855af0a2dba02782b7e6ac375a0ef41e1226147156

(this sample)

Comments