MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 885c1cf470da326b0dc71c9eb6b7d194e12ec351f8e51068d8e8d18ac7baeba9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 885c1cf470da326b0dc71c9eb6b7d194e12ec351f8e51068d8e8d18ac7baeba9
SHA3-384 hash: da5a56db4fe799ad58de6626b9cadbc4262f7c46c0d60502c015ce9656971447fb40c33d502ea3ace1b2214275545b44
SHA1 hash: 14affdac01a962347788f987fc4cdc8cb93ad138
MD5 hash: 2f71b50513c3d575b0bfea81cd8fe148
humanhash: south-aspen-east-glucose
File name:RTGS.rar
Download: download sample
Signature GuLoader
File size:44'679 bytes
First seen:2020-06-08 12:05:24 UTC
Last seen:2020-06-11 05:11:59 UTC
File type: rar
MIME type:application/x-rar
ssdeep 768:1W3rqAQcj/GkrECf08xsmGYaD9YVcn3apxP6s3m5rn2VfNTw9YpfyH+67c1pK:1krecyiEH1fDGVcb5eTw9YpaeScK
TLSH 0613F1A44E4FF9072B5686997E4038C8799346DA18FC76191962FC0E02C74B4DB8FE3A
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: goo10.de
Sending IP: 78.111.69.180
From: Mahesh Rana<purchase33@akhilhealthcare.com>
Reply-To: <purchase33@akhilhealthcare.com>
Subject: Paym'nt transfer (RTGS)
Attachment: RTGS.rar (contains "RTGS_pdf.exe")

GuLoader payload URL:
http://ratamodu.ga/~zadmin/group/gld_BJLCSDOEDs225.bin

Intelligence


File Origin
# of uploads :
4
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Spyware.FormBook
Status:
Malicious
First seen:
2020-06-08 05:51:34 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 885c1cf470da326b0dc71c9eb6b7d194e12ec351f8e51068d8e8d18ac7baeba9

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments