MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 784ecbb5c2a0878453ae9c24a32ab455a3c24ba535d84720fb7baf62ab362868. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 784ecbb5c2a0878453ae9c24a32ab455a3c24ba535d84720fb7baf62ab362868
SHA3-384 hash: 26ac2b4c4df25b3412393de24569483aace80e2035814f13723fa2fea80c9d486970041cd7d8ac335ff8c5f21d5dbf8a
SHA1 hash: 3879e671622f499c15e5e908aa1f02c51bf9fa14
MD5 hash: db24366c2dd2f7c393acf812202ac67a
humanhash: cold-crazy-angel-mockingbird
File name:Required Equipment Item Specification_8915963B.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-04 10:48:01 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:jzqSPfxV40urLpJkgrKHxLdGKc+o0FDHdZ1gIBgYQM/beDawBbMaxUgaRt:DPXWdZKVdhjFD9zkMZfoa
TLSH F1456A03ED4D8663D1444BB82D679E793B2CB91909011BDF713DAE9FAF316422C9B21E
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: server.ecomotorhk.com
Sending IP: 162.144.56.225
From: Tomoko <info@semco-ltd.com>
Reply-To: info@semco-ltd.com
Subject: Re:Re: Request for Quotation_PR#PS-AVP2-406890
Attachment: Required Equipment Item Specification_8915963B.img (contains "order.exe")

GuLoader payload URL:
http://149.255.36.133/bin_PqLAqQjAza233.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-04 11:35:54 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 784ecbb5c2a0878453ae9c24a32ab455a3c24ba535d84720fb7baf62ab362868

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments