MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9641fb32b07f79f3aaca3b8dee9cae0b806832db78f7a0104ab4ecd124a799f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9641fb32b07f79f3aaca3b8dee9cae0b806832db78f7a0104ab4ecd124a799f5
SHA3-384 hash: a70fb1b5a0b6cadd51b2d0a2bc2141db5773b03026d0c62bf1fbb1eae49befbc4b2a39b21d5ea33d592c460aecc6a310
SHA1 hash: ec3536633231c3bc18d7ce918106ca77ac03fefa
MD5 hash: 61c67b57315ee86949f60ac87b05cfae
humanhash: hawaii-alabama-emma-connecticut
File name:DHL Consignment Detail_pdf.gz
Download: download sample
Signature GuLoader
File size:38'644 bytes
First seen:2020-06-02 11:21:57 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 768:MPzutj5X1h7BRXtVGLmpoXvFmmOr6VCts0YFub+roGbn:7zzdRyq2vFuekjs19
TLSH 6303F14632B5C115B0D5CCE29B21461EF1EA178356D2476FE4218B66282B7B78BCBD38
Reporter abuse_ch
Tags:DHL GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: park-mx.above.com
Sending IP: 103.224.212.34
From: DHL Express <service@dhl.com>
Subject: DHL Consignment Details
Attachment: DHL Consignment Detail_pdf.gz (contains "DHL Consignment Detail_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=12VVxuFaEWMoS43kZAQF0T3wJzBgC7KkF

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 02:10:00 UTC
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz 9641fb32b07f79f3aaca3b8dee9cae0b806832db78f7a0104ab4ecd124a799f5

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments