MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69cd1afc4726d2b67cb755017a3b09db268070390ae269c55b895437393f2183. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 69cd1afc4726d2b67cb755017a3b09db268070390ae269c55b895437393f2183
SHA3-384 hash: f1f76e248478be95eba69c7909167271cfa40c8bb6eb5c27c8109f33889f0b884bec3b5438f0ba615028c30a392e4ab5
SHA1 hash: e57244bcade3085811f47c79db0db2e742c0652b
MD5 hash: 18330e96843411437d2af2f7bee062cd
humanhash: five-aspen-papa-beryllium
File name:Inquiry CAMC 6x4 tractor_images.rar
Download: download sample
Signature GuLoader
File size:23'887 bytes
First seen:2020-05-21 08:18:46 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:T6aRMBU6SKL8GExY3W2oOFv/gFaQfn0QpzRsxXdDe6jHmIeICFe+XA:uar6oKjJt4FpPfp18tDbGIuM+XA
TLSH A8B2E1EA76605ED2E5B2B10E4225D9056E041ECCB416EDC8D6F4E9600D6CE3B9CBCF82
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.example.com
Sending IP: 103.114.106.250
From: Kaldicafe Global Trading Co.Ltd <admin@mogioan.cf>
Subject: Re: 回复:Qotation Inquiry CAMC 6x4 tractor
Attachment: Inquiry CAMC 6x4 tractor_images.rar (contains "MISCON.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1MrHFPtz8U5_L2DReREhUhjzfOWKZqTHT

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 08:36:20 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 69cd1afc4726d2b67cb755017a3b09db268070390ae269c55b895437393f2183

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments