MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 56411e9984cfc62c18bb642ce1df394415c2067df561ed8b33b9b76063e440de. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 56411e9984cfc62c18bb642ce1df394415c2067df561ed8b33b9b76063e440de
SHA3-384 hash: 74230fa2887396f0e21a521336eb3a23fe42302c272556ad1565acf72bc034e2e437c3d10484bb1edb657e4ff0b75d10
SHA1 hash: c66f22309999c8e0c6cb09f36b019405f11f2fb1
MD5 hash: 8526f46e04fd45d7a64be9587751db36
humanhash: delaware-oscar-hot-fillet
File name:Mage Properties Order Receipt 2020172602US_pdf.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-05 19:34:21 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:h0tDrdLtwAwQOcCEMZyqaRtjwDwvmOFHzTXdzC9CnvxqvMrI91QDWuAnh:hYrdhvwQGEjNRtUEuOlzTXZLqt1+6nh
TLSH 5D45B11BB81DCB9DE2544EB1F97151F11669AF17FA40282FB2C8FE6C73B009C28916D6
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: raikenservices.tech
Sending IP: 137.220.33.175
From: payment@raikenservices.tech
Subject: RE:Payment confirmed! Mage properties #2020172602US has been shipped
Attachment: Mage Properties Order Receipt 2020172602US_pdf.img (contains "Mage Properties Order Receipt #2020172602US_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=13NDO4qABwhAw52XplbpeSGPdCx-zP9cG

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-05 19:36:05 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 56411e9984cfc62c18bb642ce1df394415c2067df561ed8b33b9b76063e440de

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments