MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e23be52a023bfdb6aa5164893b06e47f51e03f4b50e22010f923334c45417b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 7e23be52a023bfdb6aa5164893b06e47f51e03f4b50e22010f923334c45417b4
SHA3-384 hash: 481af8d806db6ceb03f4b132ab62efc1c9be08363c243d530479dcfbe38862f0dddb6c73e762583227a926c8d972e58a
SHA1 hash: 01402dbdf7e93e51bfe22490f55f019b6ede9fc3
MD5 hash: 7a1cc7c4a36e7401114b9a6bc02aeb99
humanhash: green-nine-mars-oven
File name:E-U2230-009-RFQ for Air Coolers ACHE BID DOCUMENTS.img
Download: download sample
Signature GuLoader
File size:155'648 bytes
First seen:2020-05-26 07:19:51 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:8UITtV6MIo11Una34ac7B2KLE1KoxtxF:mtrISUa3Dc7B2KL1oPxF
TLSH F3E30AA167E0ADF9E9B24FB218705650441BFC630C638A0B30CE756E1E77E4697B173A
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: cad.hagyz.com
Sending IP: 165.227.38.96
From: Reshina Jithesh <reshina.jithesh1@suez-oilandgas.com>
Reply-To: reshinajithesh.suezoilandgas@protonmail.com
Subject: Enquiry: E-U2230-009-RFQ for Air Coolers (ACHE) // L & T Sonatrach Algeria Project // KOREA HEAT EXCHANGERS
Attachment: E-U2230-009-RFQ for Air Coolers ACHE BID DOCUMENTS.img (contains "DEMODULAT.exe")

GuLoader payload URL:
http://zed2020.webredirect.org/uploud/5bab0b1d864615bab0b1d864b3/bin_LbSiaCt213.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-26 07:36:20 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 7e23be52a023bfdb6aa5164893b06e47f51e03f4b50e22010f923334c45417b4

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments