MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e6f9c96b9332cdb7bafa068de6591e073bc8255d37f22f08a796f77f9d3d63f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 2e6f9c96b9332cdb7bafa068de6591e073bc8255d37f22f08a796f77f9d3d63f
SHA3-384 hash: e0a879f295ae6d2ae3eb3939032fdb526d7cbfe045627b6940cb137aae7f4a1a70899ea3d003ce9639ea933c4a1f96a2
SHA1 hash: c8c0f274a76752d2676720b52dd2ad3b13792709
MD5 hash: 78a2177c0352a209b5e4abffc5d7cf23
humanhash: early-summer-iowa-cola
File name:SLD-E2020-0002.exe
Download: download sample
Signature GuLoader
File size:65'536 bytes
First seen:2020-06-10 06:51:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 894021bae3426f6abaf231be95b5e5ce (1 x GuLoader)
ssdeep 768:bicGMjJvbviBcF5gjN7wb9ZPGSN3BEeOAB0WeU+XiIMT69tv:b7G0tqjN0b9kSFOA0WePt
Threatray 792 similar samples on MalwareBazaar
TLSH E4534A0F6D089963E5304BB039B295A56315AC28050ABE4B7E8C7F5CEB715C3BDC332A
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: sungwon7.co
Sending IP: 111.90.158.36
From: Giulia <giulia@sungwon7.co>
Subject: please quote it based on attached template
Attachment: SLD-E2020-0002.rar (contains "SLD-E2020-0002.exe")

GuLoader payload URL:
http://111.90.146.31/rfq_LrULI174.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Occamy
Status:
Malicious
First seen:
2020-06-10 02:58:07 UTC
AV detection:
25 of 29 (86.21%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 2e6f9c96b9332cdb7bafa068de6591e073bc8255d37f22f08a796f77f9d3d63f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments