MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ed29e69e093dd3a16eab9c02e29c5a91421fac4e0cd1c5b58f80e111b00bffb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2ed29e69e093dd3a16eab9c02e29c5a91421fac4e0cd1c5b58f80e111b00bffb
SHA3-384 hash: 010042fd3f9d8399e7c8c1e12d4d59df08ed60dac0a2b101b8f05c1d821994f6779fc17b9fd4509a965ffb1971214425
SHA1 hash: f4fe8d92408ed73b734704c5acf0ddf0dbcee30e
MD5 hash: e2e0ca347a337551b600db2edb6ff235
humanhash: november-video-idaho-timing
File name:DHL_AWB 9284730931.rar
Download: download sample
Signature GuLoader
File size:38'072 bytes
First seen:2020-06-02 11:00:59 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:TnZqANe3EbVY2gK4roDj1CEIrjTAXDKAhj/M8gsI:UF3EK2Ds0j1W0zK8y
TLSH B903E136819F773FC4CDF842D26F58AA1EF4BA8E89D411B4C5A41DC4E970E3E466189C
Reporter abuse_ch
Tags:DHL GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.gtrit.com.my
Sending IP: 103.18.246.122
From: "DHL Express"<dhl1@dhl.com> 
Subject: Original Shipment Document
Attachment: DHL_AWB 9284730931.rar (contains "DHL_AWB# 9284730931.exe")

GuLoader payload URL:
https://qif.ac.ke/flow_AoGPhiVz245.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Razy
Status:
Malicious
First seen:
2020-06-03 04:02:25 UTC
AV detection:
20 of 48 (41.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 2ed29e69e093dd3a16eab9c02e29c5a91421fac4e0cd1c5b58f80e111b00bffb

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments