MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5629ec1f97b4fed71d3572fd07f8e5ca6436788e3fa2683d50a8faac33a13adc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5629ec1f97b4fed71d3572fd07f8e5ca6436788e3fa2683d50a8faac33a13adc
SHA3-384 hash: 3f87e05aab3fd2ba5aa6c8175b6151eac4dd4469bb1111cbd114e2d10bdcfc74e520f389ed80cb56e53a308e902bf165
SHA1 hash: 0873d732d4330d03335e2803aea1ed2a80f311e7
MD5 hash: 629b7afe0c9a66e10ebe73980a2c26ec
humanhash: massachusetts-lemon-juliet-ten
File name:NEW ORDER 063310 NAZIR AND SONS CO_pdf.arj
Download: download sample
Signature GuLoader
File size:76'854 bytes
First seen:2020-06-03 13:28:48 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:3q63zqOPrxrE3jyz7jaXEmt51TYo2JEqdog7iaoy1TQS8:t320rPaBdFeH7iaoiTU
TLSH 2A730287F0E52B01CB86D4F64AC25A6F43DCD3B88192ABA1AF7F4DD21F6841163161D7
Reporter abuse_ch
Tags:arj GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: s1.smallhost.in
Sending IP: 103.46.239.70
From: Nazir & Sons Co. (Turkey) <rubab.s@nazirandsons.com>
Subject: NEW ORDER #063310 NAZIR AND SONS CO.
Attachment: NEW ORDER 063310 NAZIR AND SONS CO_pdf.arj (contains "NEW ORDER #063310 NAZIR AND SONS CO_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1_MYMmXePhIt1EdobIE3aMcZnY7VJ9y-J

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-03 13:37:33 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 5629ec1f97b4fed71d3572fd07f8e5ca6436788e3fa2683d50a8faac33a13adc

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments