MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e318e1fa79f9a8bae60fa5979257a0c4289ec4752a78f77f140ba0596eaf388. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8e318e1fa79f9a8bae60fa5979257a0c4289ec4752a78f77f140ba0596eaf388
SHA3-384 hash: 2d0cfcb1262e70df94127c7e7c9bc6483e1bb240ef5479671be2a21c43092be0057e1cdc936f699684f7c8c0b170c648
SHA1 hash: 76dce68362c41804de4072c2cf8b5f54f6483f02
MD5 hash: c51e5f43a7808e24d4a01276153156bd
humanhash: april-five-july-arkansas
File name:C2-03 - TANPHAT PO-20060482446.rar
Download: download sample
Signature GuLoader
File size:75'362 bytes
First seen:2020-06-04 06:19:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 1536:XitdTq/IsLZDHGvXMq2VvZbtgbOR7a4eqSPp4VFFrsds7fQj:XitdeLZqXCOiLeqSx4VFFw40
TLSH 887312081BDA3EAD2073F548351E2F1AA3FD74D197E3228DB79524E2E10E15AAC1374B
Reporter abuse_ch
Tags:GuLoader Loki rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.goldsun.vn
Sending IP: 119.17.215.18
From: Dung, Nguyen Thi Phuong (DVK) [dung.ntp@tanphat.vn] <long.nguyenvan@goldsun.vn>
Subject: RE: Tan Phat Vietnam PO: Yêu cầu báo giá CCDC (TTĐT) - C2-03
Attachment: C2-03 - TANPHAT PO-20060482446.rar (contains "C2-01 - TSC PO-20060482446.exe")

GuLoader payload URL:
http://ratamodu.ga/~zadmin/group/harl_cyMbNbo109.bin

Loki C2:
http://egamcorps.ga/~zadmin/lmark/harley/mode.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 06:37:45 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 8e318e1fa79f9a8bae60fa5979257a0c4289ec4752a78f77f140ba0596eaf388

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments