MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7c42499db27d5fb219cfadecc2a325deabaa2ddc659f58225b7d15c35601b964. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 7c42499db27d5fb219cfadecc2a325deabaa2ddc659f58225b7d15c35601b964
SHA3-384 hash: 38bffa17dc0c73b3eb58a5622db3fb9d24c8827f4a388b7a54616e2055d7339b414027caace1ced951f84ac64b950cac
SHA1 hash: fab8f13e54c08e9010a9903154a05432153582f1
MD5 hash: ed1bc87250330bad5b4b0849e52e508a
humanhash: six-august-kentucky-lion
File name:Invoicepayment.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-21 08:50:18 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:jAMKsEpVK0kMK2w9gjLqC8WtDsYXm6JltNiKMLL+7AtC4jUf2h:0RLBwO3QGnF8KMLSAU4jUf
TLSH A745396586A0A133D9198AF02FB5976C16BCBC351A51CC4BB9CC3E4A9F76A43F52031F
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: vm9win2.securesurfs.co
Sending IP: 162.213.42.222
From: Mr. Sajid Saad <support@goldfx.co>
Reply-To: support@goldfx.co
Subject: Re: Invoice/payment
Attachment: Invoicepayment.img (contains "order.exe")

GuLoader payload URL:
http://185.236.203.160/bin_infAhIbG124.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 09:36:32 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 7c42499db27d5fb219cfadecc2a325deabaa2ddc659f58225b7d15c35601b964

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments