MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a742ca94da38331e18967b9ff230167d7893c643ff935ce8be4d05ae2c18983c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a742ca94da38331e18967b9ff230167d7893c643ff935ce8be4d05ae2c18983c
SHA3-384 hash: 23e021d16bd32e63b641608bd69adcf590e83230a6e4f7b42d73eda4a3ba1aa21566d58e827649ecfd9111e105a672ba
SHA1 hash: eba261657d82eea5f27b75bbec2559cce1e2cee9
MD5 hash: 8ae5442fd018a4af5544fa0b2e98602a
humanhash: lactose-seventeen-queen-six
File name:RFQ89234A_2021_LISTED_ITEMS_DUC_PHUCS_IMPORT_EXPORT_CO.arj
Download: download sample
Signature GuLoader
File size:26'693 bytes
First seen:2021-01-14 06:56:46 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 768:6Ygj7op6Fde8LUicva9WL9aWV1Qv/L/faG1Y4mbN4g:+7op6nRLnqa9W4WVKrfaG1O4g
TLSH 7AC2E17F25F6E4611D31F5EA00EB89314D6D1540426CFB5E3A1F07074F1D73AAAA0AA1
Reporter abuse_ch
Tags:arj GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: vm1756875.nvme.had.yt
Sending IP: 185.209.23.184
From: Traân troïng <sales.phatdt58@gmail.com>
Subject: REQUEST FOR QUOTATION (RFQ#38787-A)
Attachment: RFQ89234A_2021_LISTED_ITEMS_DUC_PHUCS_IMPORT_EXPORT_CO.arj (contains "RFQ#89234A_2021_LISTED_ITEMS_DUC_PHUCS_IMPORT_EXPORT_CO.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=A951308400164DD4&resid=A951308400164DD4%21106&authkey=APE43C5aWsOop18

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Midie
Status:
Malicious
First seen:
2021-01-14 06:57:07 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

arj a742ca94da38331e18967b9ff230167d7893c643ff935ce8be4d05ae2c18983c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments