MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67271c5fad92ba3a14c3bd869fde6d30599504389ce5d18ba2b33c4e4ff2f857. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 67271c5fad92ba3a14c3bd869fde6d30599504389ce5d18ba2b33c4e4ff2f857
SHA3-384 hash: dfe8a430217f062fa5a980a78ad1ddc13a2d6959417ddd8359d9b8518581032437f4a62d362670f4ef5a81273b3afff4
SHA1 hash: 5b7670843229d8c1a1ca73fc6f289f1cbefd4695
MD5 hash: c54422612734c9bf671e1130e71f6b3b
humanhash: romeo-virginia-stairway-kilo
File name:req 20934083.rar
Download: download sample
Signature GuLoader
File size:22'013 bytes
First seen:2020-11-13 08:31:41 UTC
Last seen:2020-11-16 06:41:37 UTC
File type: rar
MIME type:application/x-rar
ssdeep 384:ztQl9Tkiy+ISfEXcLzbpO5Z5U3gPut1Bs6Cc8ze:ztQLTkBinUKyut1cNa
TLSH 95A2D079BBA17A235D4AF737BB470608C6183BDE75D90F38882C07AFC47B648995204E
Reporter GovCERT_CH
Tags:GuLoader

Intelligence


File Origin
# of uploads :
5
# of downloads :
193
Origin country :
n/a
Vendor Threat Intelligence
Result
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-11-13 01:27:40 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 67271c5fad92ba3a14c3bd869fde6d30599504389ce5d18ba2b33c4e4ff2f857

(this sample)

  
Dropped by
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments