MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 58111c511d6314009903fd52e95aa2f531acbb7886e0c0342914837dbf0d3f86. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 58111c511d6314009903fd52e95aa2f531acbb7886e0c0342914837dbf0d3f86
SHA3-384 hash: e8dfe13f67ab6d4848a785708e0cd615750c898c4255805339632174e4ccdcbbae63af07cc67f35a84b383b85d6ebaf8
SHA1 hash: bffe059d53fa37860b9e1cf57403ff3be6425299
MD5 hash: 61c423a3de2ed7bdbd89d74716564aa1
humanhash: jupiter-speaker-social-six
File name:DOOYOUN CORPORATION Emergency ProductionRequest.img
Download: download sample
Signature GuLoader
File size:147'456 bytes
First seen:2020-05-27 15:57:59 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:4p1psaKFPS8YpWttb9X+5UR2AJAweAjFiYBAkGLdbmShtOXepQIt044xOCVZ0H9:oqPWpq9uKJfWddSOpQIt0uyE
TLSH E4E32913B9650DA1E80241B0CCA2D3EF16D77D215C564F0FB68C3A6C6BBB6822DE531A
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.richermoren.gq
Sending IP: 64.52.172.142
From: Jaeho Lee <reshina.jithesh@suez-oilandgas.com>
Reply-To: casmirfatih@gmail.com
Subject: DOOYOUN CORPORATION Emergency Production Request
Attachment: DOOYOUN CORPORATION Emergency Production Request.img (contains "DOOYOUN CORPORATION Emergency Production Request.exe")

GuLoader payload URL:
http://izpanelone.webredirect.org/uploud/5bab0b1d864615bab0b1d864b3/bin_LtTlZ208.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Mbt
Status:
Malicious
First seen:
2020-05-27 16:35:33 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
16 of 48 (33.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 58111c511d6314009903fd52e95aa2f531acbb7886e0c0342914837dbf0d3f86

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments