MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8e386ad757f3fa77a6dc942cf3449dcd992aa69d2aa17f4bb5e3c5da36eed95b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8e386ad757f3fa77a6dc942cf3449dcd992aa69d2aa17f4bb5e3c5da36eed95b
SHA3-384 hash: 1c581790bd403f38292b21dc00503820edf86c36b5aa06682e852912fbc7e976d44d1ada0b1c6d2654a1afcb7d297840
SHA1 hash: 9f6c6f01892579476484a9d547476d7453787cc2
MD5 hash: 218243876d44d493bac78b0059accc02
humanhash: carpet-charlie-earth-beer
File name:INV.202005.7780.DOC.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-08 12:04:46 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:UXysfNpuRnnPilTjATM/q4LHdcxTjQMBpDpTkRXQJtEWx4Be3KO+oiezDg5sYHeN:UXysFY6TjMiXYTMM/p0goKKoiBe
TLSH F8459E0BAC04C572F14086B15D938B6A2326692869439F973A5D1FAFEF703C35FE522D
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: myuncommon.favour.com127.0.0.1
Sending IP: 2.56.8.246
From: info@vinco.cc
Subject: Pagamento Recusado
Attachment: INV.202005.7780.DOC.img (contains "INV.202005.7780.DOC.exe")

GuLoader payload URL:
https://onedrive.live.com/Download?cid=3BCD34D8AC2D7789&resid=3BCD34D8AC2D7789%21435&authkey=ADMsJhgPkBTcqZs

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 12:06:06 UTC
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 8e386ad757f3fa77a6dc942cf3449dcd992aa69d2aa17f4bb5e3c5da36eed95b

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments