MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ae0e343964f7a0504f73c030f70e4a60d02413070d3b166b04933e4a97ad1ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8ae0e343964f7a0504f73c030f70e4a60d02413070d3b166b04933e4a97ad1ae
SHA3-384 hash: 84d2c83acf9fcbd7aa328118a2d2cf4d49cda0640bb8a6946f38e7385b577b553f06764a0239fb084862deeee69bc95d
SHA1 hash: bbe52e5f006220abbd15ea94b04681b85fe2e7bc
MD5 hash: 5b70468d88699ee3d4a22ae237b6b06d
humanhash: juliet-washington-artist-mango
File name:Documents-DHL950446602.pdf.gz
Download: download sample
Signature GuLoader
File size:85'988 bytes
First seen:2020-06-04 17:21:21 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 1536:03EFOwqf8qNod39wqIEyJtJR/VAY6euuKFjdOhZ+mt4uXKT3MEOzWP415r:0Ylqf8qNod3GXt3/VAYNKIZ+mGuXKth8
TLSH 1183021553ABE2D7C7D27383DD19476AE3C8674ECAAC42F62F6224479CE0A580BE0475
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: aa98419.online-server.cloud
Sending IP: 74.208.129.40
From: billing <billing.expressec@dhl.com>
Subject: New Shipment Documents-DHL950446602
Attachment: Documents-DHL950446602.pdf.gz (contains "Documents-DHL950446602.pdf.bat")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1VdC4d-TeIQw6TVXtRDDzA75YjPybguoL

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 17:36:13 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 8ae0e343964f7a0504f73c030f70e4a60d02413070d3b166b04933e4a97ad1ae

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments