MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 55fd2a7da2d6e586d9dab45af4f6972664179cb02bcada5a4072ffbef2676902. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 55fd2a7da2d6e586d9dab45af4f6972664179cb02bcada5a4072ffbef2676902
SHA3-384 hash: b020d62b2925683b05d259c5aec11a7f72c9d8f8e7622a629f785378573b5678e8649ef06783637a077ed875151c043d
SHA1 hash: 7d8241beddf013084dc89d15c0263b74a5370140
MD5 hash: b67d351f3abaf888c7eeb72bc395d01a
humanhash: uranus-hot-emma-mississippi
File name:3-6-2020pdf.zip
Download: download sample
Signature GuLoader
File size:39'776 bytes
First seen:2020-06-03 13:29:56 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:SYA+YiZ8QA2CvA+O676XPtRg5ZIn7z+HPp+hJh0YPkDhQM:SYA+LhXPt+KnWvEhjeDhQM
TLSH F403F1DF62AA4BD7DB838A15B38425E08BFD7BB115A548C1F33E6617274390B8920473
Reporter abuse_ch
Tags:geo GRC GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: cloud.zeosing.com
Sending IP: 147.135.220.238
From: Αριστοτέλειο Πανεπιστήμιο Θεσσαλονίκης <webmaster@auth.gr>
Subject: ΑΙΤΗΣΗ ΓΙΑ ΠΡΟΣΦΟΡΑ (Αριστοτέλειο Πανεπιστήμιο Θεσσαλονίκης) EUI894/BU4633
Attachment: 3-6-2020pdf.zip (contains "Cocoricoepini4 (1).exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1hr0pLKOXvWXtnfKBZBtOt9IncEBTVDxv

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 13:37:31 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 55fd2a7da2d6e586d9dab45af4f6972664179cb02bcada5a4072ffbef2676902

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments