MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 65446f37d51ec678a67d994250fdbe6253de6dead6bb2b1d8d101f212fbb73ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 65446f37d51ec678a67d994250fdbe6253de6dead6bb2b1d8d101f212fbb73ad
SHA3-384 hash: fa531aa0d5dcfd409cb7408890b1f4eacb32000f74513ff653eaa52eb9ca2dc47a91a5dd0552e5b0ae6759e7d4ad0d16
SHA1 hash: 3a63f8159751c060b5b0136eaa1859c6c8d5366f
MD5 hash: 47564c62e597361d33d77a011fbd7459
humanhash: aspen-kilo-fruit-utah
File name:file.IMG
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-12 16:18:33 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:EqTtvu8ixS4G2c8LLGEeAIyeHiBlA/y6WEuIf0l7XLHt:68ixSf2LGEeAIyblOWhP5
TLSH 30454A4376B0E13BE204CAB21F65A7946566BC302951C903F9CC3B2D1B3AB56EA3571F
Reporter abuse_ch
Tags:geo GuLoader img KOR


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm80.hanmail.net
Sending IP: 211.231.106.155
From: 비 엘 두 주 식 회 사 <kidsnuri0055@daum.net>
Subject: 견적용입니다 긴급\x0a으로 견적만 주세요
Attachment: file.IMG (contains "WT_purchase_order.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-12 03:05:39 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 65446f37d51ec678a67d994250fdbe6253de6dead6bb2b1d8d101f212fbb73ad

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments