MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71a64f7df46db361182074e7f146e186bbc67ffab5b787a3644cb79b77cbe721. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 71a64f7df46db361182074e7f146e186bbc67ffab5b787a3644cb79b77cbe721
SHA3-384 hash: 098927cb3319989fa25ed8ad98814fb632812ce099aae56c78fe2aedb6f0d5833ee85d10d1ab0d9384fac31bda4c0f3b
SHA1 hash: 90f15c139a2bdb9cc53781bb93166e485919986a
MD5 hash: 9c1c7de792c33af8a5a4add7cf16feee
humanhash: pennsylvania-lithium-thirteen-low
File name:견적 제출건(저스트)HYUNDAI MASS QUARANTREAT PROJECT.dwg.dwg
Download: download sample
Signature GuLoader
File size:30'216 bytes
First seen:2020-06-10 06:51:08 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:BYoInVhAcFavNU1UAd8e8kH27WM1Pi2JN7lUEmaTP:By3AZUeAd180LMk2j7lUFaTP
TLSH 68D2E119EFDDDB023E099CF0B3C5E68A530DE15E9358A4ACB4582707B9E193D0D56983
Reporter abuse_ch
Tags:dwg geo GuLoader KOR


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm50.hanmail.net
Sending IP: 203.133.180.238
From: 로이 유 <km4216@hanmail.net>
Subject: 견적요청의 件:HYUNDAI MASS QUARANTREAT PROJECT
Attachment: 견적 제출건(저스트)HYUNDAI MASS QUARANTREAT PROJECT.dwg.dwg (contains "견적 제출건(저스트)HYUNDAI MASS QUARANTREAT PROJECT.dwg.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1MlZro8vkFl7QfSDJyCrAhonEAsXg334X

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-10 06:52:13 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 71a64f7df46db361182074e7f146e186bbc67ffab5b787a3644cb79b77cbe721

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments