MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f2bd88edd485802f338232663ed792f4dda06406710a306d19a575c7afc5cc1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3f2bd88edd485802f338232663ed792f4dda06406710a306d19a575c7afc5cc1
SHA3-384 hash: 635c8a627f8780a488b9c01cebe833dea00d9583c2521be3d56e77f6fc18395725b6752c81a00b40d437379d81f5ca3c
SHA1 hash: 95b986294ac8c2ffc256640c9cffd29eea9ef5fb
MD5 hash: 3ff6335fba58a49fa5b0ed4f17443e03
humanhash: mississippi-black-alaska-hawaii
File name:New Order.zip
Download: download sample
Signature GuLoader
File size:33'980 bytes
First seen:2020-08-05 12:07:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:xX+h4muWTYNrBlH2ir1upIZJUtOWj2dgUtduBlF:gh4mJUEAs1tOWjUtdIF
TLSH D9E2F1C97E5FE8DBDBC521403901A6BB90E4F7360C375B890E4476B282952A7EA72C61
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: del27.i.mail.ru
Sending IP: 185.5.137.73
From: ГУ Объединение Минскмелиоводхоз <minsk.melio@mail.ru>
Reply-To: ГУ Объединение Минскмелиоводхоз <minsk.melio@mail.ru>
Subject: New Order.zip
Attachment: New Order.zip (contains "New Order.com")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1J0yGXoItb8-2VNCrcSnWWQpYZ4TkX8BE

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Malware.Doris
Status:
Suspicious
First seen:
2020-08-05 12:09:08 UTC
AV detection:
5 of 48 (10.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 3f2bd88edd485802f338232663ed792f4dda06406710a306d19a575c7afc5cc1

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments