MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 685dc737184ee2a1dbf42267b80cb6439e113e7a09e9827f537c143bc689903f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 685dc737184ee2a1dbf42267b80cb6439e113e7a09e9827f537c143bc689903f
SHA3-384 hash: ffae8726d813ca48c6fd1fc454041a7c01cd2612959a41741f7da6a0ec4def77989536f2a5bd62772791830057cd50d7
SHA1 hash: 2d41f42c55c3e9cac302a8092c1dd115b74d4ebd
MD5 hash: 58820dfe5ae549668d460e4f988ed617
humanhash: spaghetti-comet-summer-timing
File name:file
Download: download sample
Signature GuLoader
File size:32'361 bytes
First seen:2021-01-20 20:45:03 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:doph+EU6yy/Cnzlop7pl9TqYGwORMT1zz6jUmUpgYGhGtYgKW:doph3fT2ajkRMT1f6jUnihGtYgz
TLSH 9DE2F15F7AA5604B441540D00497F9B394B760172A293CBD8F38BFCF9E45FD06A26BE4
Reporter fabjer
Tags:arj

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2021-01-20 20:37:28 UTC
AV detection:
11 of 47 (23.40%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 685dc737184ee2a1dbf42267b80cb6439e113e7a09e9827f537c143bc689903f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments