MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9e28c66bf87ac2f3546bf1a082c03a7a828fde35e243f848735c19615846e754. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 9e28c66bf87ac2f3546bf1a082c03a7a828fde35e243f848735c19615846e754
SHA3-384 hash: 1a24b5a8489d70f6c5ebf7ca82cae183fbde906d8d975cf84e041362b058115bc78217f042c1c2b81cc20b377d15617e
SHA1 hash: 18c9df7df305e9007a6aacbbaf24917f5067f61b
MD5 hash: 36e33116c1896437f17586dd8e85e59f
humanhash: oscar-juliet-winter-wyoming
File name:Inv-PO021249.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-06-08 14:49:57 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 1536:CuRtSpQSwnneqZria0WKLy1EJuVNUcSDBsW:7yVeeiUXSW
TLSH 52456B376E04C102F20506F12CA2A9651676BC165880AECF324D7E5F7BF225E6D66F1F
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: smtp125.iad3b.emailsrvr.com
Sending IP: 146.20.161.125
From: Suzanne <support@lecuy.org>
Subject: Invoice PO021249
Attachment: Inv-PO021249.img (contains "Inv-PO021249.exe")

GuLoader payload URL:
http://www.filefactory.com/file/6zg94cfexkq1/tekashi_zYfAEyH47.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-08 14:51:05 UTC
AV detection:
14 of 31 (45.16%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img 9e28c66bf87ac2f3546bf1a082c03a7a828fde35e243f848735c19615846e754

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments