MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3df235355cad362b714ae2dc8a932be04e03e15246f62498a45b0b9490f87ca3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 3df235355cad362b714ae2dc8a932be04e03e15246f62498a45b0b9490f87ca3
SHA3-384 hash: ebf749330959062da5e7337c9dc576b9ec82076fd74a29179d7099015ff1182b255bea7c8b53850fcc39abdf1d87f50a
SHA1 hash: 653f97063a1f66ccb0029d00b82055ec872a7761
MD5 hash: b62375c2af9c1d41f644d13c864e1fb8
humanhash: cat-sweet-west-sweet
File name:attachments.zip
Download: download sample
Signature GuLoader
File size:57'640 bytes
First seen:2020-06-01 08:26:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:b5rZjJ+MzZSa3v5PjaEJhfCY4r5rZjJ+MzZSa3v5PjaEJhfCY4i:bVJYMsuhPbXfCJrVJYMsuhPbXfCJi
TLSH 2C43E15D651DC8275C7DFA3D7A490F84610184276A2AED9B17ECFBCAC576FCA0CA80C2
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

From: Sergei Koldenhof <purchase01@hatraco.com>
Reply-To: Sergei Koldenhof <purchase01@hatraco.com>, Sales02<amaco1990@bk.ru>
Subject: RE: RFQ:PR/JSNN/340620-Hatraco
Attachment: attachments.zip (contains "HATRACO PRICE LIST.com")

GuLoader payload URL:
https://tehrimfatimaassociates.com/amara_INllbu59.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-01 08:36:27 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 3df235355cad362b714ae2dc8a932be04e03e15246f62498a45b0b9490f87ca3

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments