MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 39fc174bbfc0ebdc3931f97e6f6f1c8b15447d80d8822f83b952c8638e668614. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 39fc174bbfc0ebdc3931f97e6f6f1c8b15447d80d8822f83b952c8638e668614
SHA3-384 hash: 70615edc58223cfa22ba4a41e8351a7928c6a6b17318b2d737aba56aefd35179f8d1fa541f048a960185c29aa673f40d
SHA1 hash: 92e1685a1214c537e5b34cdf618ebb7c65887cd9
MD5 hash: a1f2ab0a8dab17bf483467de24a0f302
humanhash: speaker-blue-harry-edward
File name:May_Account_statement_report_images.zip
Download: download sample
Signature GuLoader
File size:48'909 bytes
First seen:2020-06-08 19:00:14 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:/trESCJLZrdek26HAW5yHpFf0Y77z+PvkZcNi/Edb5z6n2/VjNn0VT95BlyW8S:/tKJLJdefHpNp77S3kONioJzhNnwR59/
TLSH EE230143ABE6185E393F3DD9A38827FD90517108416B2F4338D66B2CE6518C323EE48B
Reporter abuse_ch
Tags:GuLoader HSBC zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.genopem.cf
Sending IP: 89.40.115.18
From: HSBC BANK <admin@genopem.cf>
Subject: Monthly Statement of Account for the month of May-2020
Attachment: May_Account_statement_report_images.zip (contains "May_Account_statement_report_images.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=11mLud_us9GXVJlVXhwEf_W4AN7isn7cP

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2020-06-08 19:02:08 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 39fc174bbfc0ebdc3931f97e6f6f1c8b15447d80d8822f83b952c8638e668614

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments