MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 644eefdc34d8d71af2cb639411ecaf6d00e6092acd60594353e47ea5a836fffd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 644eefdc34d8d71af2cb639411ecaf6d00e6092acd60594353e47ea5a836fffd
SHA3-384 hash: 220612791073b4523a5542bccf61c6d288bf6d723cbd4793548651722648e846eba78724ee4b0d4a8f45024783d283f1
SHA1 hash: 1a6956f1b812fc3075e7f72f8ff72c09687b787c
MD5 hash: 5a6f179dac6ed66c98eb16eea4280bcc
humanhash: east-washington-king-virginia
File name:DHL Arrival shipment.gz
Download: download sample
Signature GuLoader
File size:43'309 bytes
First seen:2020-06-07 19:51:06 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 768:wbMGrYNOYI1pHdn/vvxM/TlXaI8veRByrrjUXo8LGBYffTymN7lLSYIhdz:TQYgYmpH13pSTlXxR4rfUX682+7lqz
TLSH 6F1302207025BCAFC69B122BBF3CD54A57561894616306B479B06FCE93F0A70B72EF94
Reporter abuse_ch
Tags:DHL GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: airgalaxy.com.bd
Sending IP: 167.114.52.13
From: DHL EXPRESS <dac.ofrdocalert@dhl.com>
Subject: DHL Arrival Notice// House Waybill/bill of lading// Import DGF customer Invoice
Attachment: DHL Arrival shipment.gz (contains "DHL Arrival shipment.exe")

GuLoader payload URL:
https://kinansreview.com/build_NEW_gLpjIcLUO232.bin
https://cmdtech.com.vn/build_NEW_gLpjIcLUO232.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-06 04:21:32 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 644eefdc34d8d71af2cb639411ecaf6d00e6092acd60594353e47ea5a836fffd

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments