MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81254ec12347967deb4e7035cb7e28fe1495a9ef705598a7a1abb4821c84e3c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 81254ec12347967deb4e7035cb7e28fe1495a9ef705598a7a1abb4821c84e3c9
SHA3-384 hash: ae6f19aa32051dfbf24cf7bf9a5051c3347b9b4482dd7e9afe1e26dadf0fcd88eec2b2e507631f68eab3fba2f9631cc6
SHA1 hash: acb268f60d4248c6129d1af8d3643399ff5d2d39
MD5 hash: 6c9a5df88bfe3bd66608e1958dff2b66
humanhash: one-march-texas-missouri
File name:ACCOUNTS SWIFT COPY PDF.iso
Download: download sample
Signature GuLoader
File size:147'456 bytes
First seen:2020-06-08 14:48:14 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 768:wonsu1aL3mNtlrHBOj1M1GBqWJgvBlwZTHi6Jbo2vDLaPNY62s5p1xLXZJJkw:/suRtSu1QsWZriabHHaq62s5p1xLXZj
TLSH E5E37C177A15C912E10006B02CE3AE252B73BD1548A16F4B728DBD4FDBBB7423DB6729
Reporter abuse_ch
Tags:GuLoader iso


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: WIN-19RHAIQ62L3
Sending IP: 180.214.239.204
From: Accounts <admin@genobose.cf>
Reply-To: kimhilary164ever@gmail.com
Subject: RE: Final Swiftcopy $40,700
Attachment: ACCOUNTS SWIFT COPY PDF.iso (contains "ACCOUNTS SWIFT COPY PDF.exe")

GuLoader payload URL:
https://www.wewilltransportit.com/bin_0.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-08 14:50:09 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso 81254ec12347967deb4e7035cb7e28fe1495a9ef705598a7a1abb4821c84e3c9

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments