MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 40066c1555d7a8db97e3b4d88de12c2fcd252adb9e811564d5527de8108fa0d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 1 File information 4 Yara Comments

SHA256 hash: 40066c1555d7a8db97e3b4d88de12c2fcd252adb9e811564d5527de8108fa0d2
SHA1 hash: c5401538c4fdff6154ce9dfb779a025017c65e50
MD5 hash: f336daf0da22ae9235c08830d4160d27
File name:PAYMENT COPY.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-05-23 11:49:50 UTC
Last seen:2020-05-23 13:13:15 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5f9cd2fbc53c0881512078ccab3f8f8a
ssdeep 768:zNw+kCzI6b3LreDqERyRl3DXvuUxLct5jjVOxRJel5OLH4HOpHLbvdFq:OsTW7crDXzxLg564Srd4
TLSH D7935A66B960EE7BCAB04EF119358974442BFCB16C020F0772CA3B5D193258D96B63D7
Reporter @abuse_ch
Tags:exe GuLoader

Malspam distributing GuLoader:

Sending IP:
Subject: PAYMENT
Attachment: PAYMENT COPY.r00 (contains "PAYMENT COPY.exe")

GuLoader payload URL:


Mail intelligence
Trap location Impact
Global Low
# of uploads 2
# of downloads 21
Origin country US US
ClamAV PUA.Win.Packer.ProtectSharewar-2
VirusTotal:Virustotal results 22.22%

File information

The table below shows additional information about this malware sample such as delivery method and external references.



Executable exe 40066c1555d7a8db97e3b4d88de12c2fcd252adb9e811564d5527de8108fa0d2

(this sample)

Delivery method
Distributed via e-mail attachment