MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a1fa35e073a5efce9ea5dabc48d35baa81ad4f0a6940202d9d812563fca37989. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a1fa35e073a5efce9ea5dabc48d35baa81ad4f0a6940202d9d812563fca37989
SHA3-384 hash: 6d2b071389ed1683a061a4c8c1885ca70e1144a28f270851ef085ca51350cc2168482b93ee19ff307d2d0efc9303c2a4
SHA1 hash: f6dcd064462cc59d1cf1a578a12d05b2069c5e18
MD5 hash: 7e3c1d58f519c68ca66e95ff973ce63e
humanhash: lima-earth-fourteen-william
File name:20200518_PO1757612.tbz.z
Download: download sample
Signature GuLoader
File size:86'184 bytes
First seen:2020-06-04 15:51:20 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 1536:ZKW6hdSqahfkx/vVYelT89ht0DDADuy1Bh8b6WO0JJP7BMVL0R:f6hQhfiVpZoDH1P8bvtVMVgR
TLSH E9831245B0B753C6029813F8F884B2F14A4FAA36B47EAD4E7AF6E7C1796C465C472C12
Reporter abuse_ch
Tags:GuLoader z


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: smtpout14.dnsserver.eu
Sending IP: 92.240.253.168
From: tanto@tanto.sk
Subject: RFQ DO200184-URGENT PROJECT
Attachment: 20200518_PO1757612.tbz.z (contains "20200518_PO1757612.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=EAD0E1196BD04320&resid=EAD0E1196BD04320%211219&authkey=AKgo75RMvr4khlc

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 16:36:49 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

z a1fa35e073a5efce9ea5dabc48d35baa81ad4f0a6940202d9d812563fca37989

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments