MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8893982594dbace5d7a77b82bd54f68ed2f282c09e830aef91c78f6b98f5011d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8893982594dbace5d7a77b82bd54f68ed2f282c09e830aef91c78f6b98f5011d
SHA3-384 hash: 36a6692326a7fb1c90246946989f7b436ee5b4eccfbfadddef9fd1299bc865de1a8aba1e14d41d53dcb828f980a2238e
SHA1 hash: d11aab262401b5a520be8e8e1f16998956e37034
MD5 hash: 7cc50904257dfdf2ed21cf674768c818
humanhash: nuts-blue-nevada-seventeen
File name:GB20200602.cab
Download: download sample
Signature GuLoader
File size:41'081 bytes
First seen:2020-06-02 11:26:00 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 768:31IAotfCG1Os8HU6zyRUcMeBQD8nnr16ZmGpURS97sxFzpiKRB1Mf:31IFtfhf6+RhQYnp83URJQf
TLSH F903F16907C2081CEB4870F8A77E16CF80B31D4717EE94BAADBF2C758162068B7D1847
Reporter abuse_ch
Tags:cab geo GuLoader KOR


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: linux1.hiya.digital
Sending IP: 72.52.131.205
From: Yeong <rafal.gasior@astoria.pl>
Subject: PO162510--컴텍_매수_주문
Attachment: GB20200602.cab (contains "GB20200602.exe")

GuLoader payload URL:
http://ekenefb34logs.webredirect.org/uploud/5bab0b1d864615bab0b1d864b3/gambo_FguXrzR169.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-02 08:37:24 UTC
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

cab 8893982594dbace5d7a77b82bd54f68ed2f282c09e830aef91c78f6b98f5011d

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments