MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8f4abfc3a0229df9fac1624288fc794048c80cb72247a04ca3378a7816546bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a8f4abfc3a0229df9fac1624288fc794048c80cb72247a04ca3378a7816546bc
SHA3-384 hash: fb3729a7c3520314fa3ccab03a013d3b2f89efe226e828fcf2bf8d76107f498f19af90bc2610cba7aaa18d1b3fa66a3f
SHA1 hash: 54e55dda09d805021d445fc6d55cda70bea86a6e
MD5 hash: 1cfb050f40698e01228fa3ba0aba796a
humanhash: sierra-william-venus-east
File name:Consignment Invoice.iso
Download: download sample
Signature GuLoader
File size:44'730 bytes
First seen:2020-06-08 09:18:50 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:Yba7o9WKTi72I+3+Da1JuPla+NYu6gtowb7spUugsmXyfr1TAvCM6W:l7B3Dah+Nr6Wb74g8Gvf6W
TLSH 5E1301EA7E741E058BD8AC80346DF4F670ABA498B9ED86F80F12008048A4F95EC17DB0
Reporter abuse_ch
Tags:GuLoader iso TNT


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail0.565.zizospanltd.casa
Sending IP: 178.128.28.120
From: TNT Express Delivery <invoicing@tnt.com>
Subject: TNT Express Delivery: You have a package
Attachment: Consignment Invoice.iso (contains "Consignment Invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 09:20:06 UTC
AV detection:
20 of 31 (64.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar a8f4abfc3a0229df9fac1624288fc794048c80cb72247a04ca3378a7816546bc

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments