MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3defe0347390f7f3c83cb66655182ececba8d67dfb84ff8d9783a79247d62901. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3defe0347390f7f3c83cb66655182ececba8d67dfb84ff8d9783a79247d62901
SHA3-384 hash: 115ef2dabd19ce502ddf07a3e26f6e23188159a20dbfc372a2ad57a93be9e10b2420d6d356258273e5264c3fde898358
SHA1 hash: 396e9280cc481366f9b1654ed74b035db110e9fd
MD5 hash: eebad852f524701ac88edd7c15cd9809
humanhash: triple-michigan-sierra-neptune
File name:INV20200406PO289.img
Download: download sample
Signature GuLoader
File size:184'320 bytes
First seen:2020-06-04 15:55:53 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 3072:jfEcuDynxa26YjHotk3PV55hkXuwvKitiPtE:jscuDwlNjIS3PV6z1tiV
TLSH 67045B032C6CCB15D19519F07CA39D5D36176A089E412AAF208CEFFFAE70691ACD661F
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail2.bm-cheap.site
Sending IP: 62.173.139.217
From: Monruethai Kate <sales@slipring.co.kr>
Subject: Rev-Order-june-04-06-20-Quote
Attachment: INV20200406PO289.img (contains "INV20200406PO289.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1k5J_vscIyT4PBUvFkrVjMmdI187aQ9mw

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 12:41:24 UTC
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 3defe0347390f7f3c83cb66655182ececba8d67dfb84ff8d9783a79247d62901

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments