MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5be931631728bae2a1c9c82e8257cffb950b804c8ad28075da587ec04bf56d02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5be931631728bae2a1c9c82e8257cffb950b804c8ad28075da587ec04bf56d02
SHA3-384 hash: fbe3de5a6933a8cb2ea7f92aaf7a6908e61488146ac2e02d5527c5a55664237dcedf38412f48538e6ad397a1fba8aee0
SHA1 hash: e53d20f6fe6d2e060368cf8a7f27e995ae1f1220
MD5 hash: 01f32d6463e407c27dc292249bd08500
humanhash: may-kansas-zulu-victor
File name:Reminder Notice for Payment Defaulter.zip
Download: download sample
Signature GuLoader
File size:89'029 bytes
First seen:2020-06-04 15:54:46 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:eqinhR1K4jqcCh8Js7zCNCkXF9WOQiHA/VuvUjIRNJ3M1X:tEkXEs7mN5XF9Wf/V8UMup
TLSH 469302A7F10B0ADF75F3AD9B585F150A6D97D2F0DFB7019330666A8B500FD5A888A031
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: kra.go.ke
Sending IP: 103.207.38.152
From: <admin.itax2@kra.go.ke>
Subject: Reminder Notice for Payment Defaulter for Obligation Value Added Tax (VAT) and period 01/01/2020 to 31/01/2020
Attachment: Reminder Notice for Payment Defaulter.zip (contains "Reminder Notice for Payment Defaulter.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1CITKldez66BgvXXT9ylfqvoseGuL_n4d

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 15:54:24 UTC
AV detection:
8 of 48 (16.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 5be931631728bae2a1c9c82e8257cffb950b804c8ad28075da587ec04bf56d02

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments