MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 699c1cebb4ccadd91e32dd928338f804655b14a53422d7483bdbc36da63ed37f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 699c1cebb4ccadd91e32dd928338f804655b14a53422d7483bdbc36da63ed37f
SHA3-384 hash: dccc0658629fa9c0bacdaac78538c24e02307ded73472d26ab3180727a7444bdfe7adb12c48b8a93d74cfe702e7bf71a
SHA1 hash: 03929c5aa1f52f766073653a0c2b72059e4c2e22
MD5 hash: ffae6f898252c2790890a6fcb5af5809
humanhash: autumn-ceiling-apart-lion
File name:Salary.zip
Download: download sample
Signature GuLoader
File size:48'371 bytes
First seen:2020-06-08 18:59:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:aYHmszQJbxlbg+yqS2TwyP2V8ww/8YNre3OjhXN5M4DxNPg7YO1Q:aYHmszANls+hSitdb8WnlX4p0F
TLSH 0F23F177110C0270FFB966A2E0CAC6422DD77A4119D315E587B4E6ACD3BBBCED2706A1
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

From: HR Manager <Hr@bottega-digitale.it>
Subject: YOUR EMPLOYMENT STATUS
Attachment: Salary.zip (contains "Salary.exe")

GuLoader payload URL:
https://learnaboutseo.org/sbUGObin.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-08 19:01:05 UTC
AV detection:
19 of 28 (67.86%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 699c1cebb4ccadd91e32dd928338f804655b14a53422d7483bdbc36da63ed37f

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments