MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 344c0e2c5b5f82724603b1a630e9e1bde4f75f7b24205e95a10b4f981306b039. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 344c0e2c5b5f82724603b1a630e9e1bde4f75f7b24205e95a10b4f981306b039
SHA3-384 hash: e5a7089c9207878e1a9e598d73601fa6cc17d051b752b4d61a44fb723f86fc5b67c33c790dd9208056a77ac0ebabdc09
SHA1 hash: 5f348d8f08e01f02c1e753eac1b48e93e5492792
MD5 hash: 5ada50e14fc2ca5b01e15fe0b9ee5c43
humanhash: pennsylvania-sweet-wisconsin-triple
File name:TNT Original Invoice.gz
Download: download sample
Signature GuLoader
File size:28'195 bytes
First seen:2020-06-01 08:26:43 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 768:TtCbaBDubEoPrMHpHD3DbLp54Q/0FE0IwzC/uN5j:RaalmPaBjDbHhYrzYuNB
TLSH 83C2E148593400B3F818652F9882BA95221BFF681D8C1527AB8D50FFB311A57AF913BD
Reporter abuse_ch
Tags:GuLoader gz TNT


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail0.342.drointernational.casa
Sending IP: 167.71.227.207
From: TNT Shipment Notification<shipment@342.drointernational.casa>
Subject: TNT Consignment Notification for 243740512
Attachment: TNT Original Invoice.gz (contains "gunzipped")

GuLoader payload URL:
https://cmdtech.com.vn/KEL_OVsbHQys31.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-01 01:22:00 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 344c0e2c5b5f82724603b1a630e9e1bde4f75f7b24205e95a10b4f981306b039

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments