MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a99ab2e8d5db3ced555cb7968881064f418c90133b3e3af5a2beb3befb79f21c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a99ab2e8d5db3ced555cb7968881064f418c90133b3e3af5a2beb3befb79f21c
SHA3-384 hash: dc6aef9182e452c36716babf8ddfc6a6f674e4da2a76b172f8c0aadbc17dbee674185af5d98bbc82f61ec43176f4ce45
SHA1 hash: ede445d91dac4d31089c16a4abb09ca6a102ecd2
MD5 hash: aaf59e216d742b27fb76b403f2246f93
humanhash: queen-item-mars-louisiana
File name:Payment Advice Note from 0324098457.pdf.z
Download: download sample
Signature GuLoader
File size:25'913 bytes
First seen:2020-04-02 04:20:32 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 384:iPScxvf7VJOqdEWKGSYxZoP9FstpwKJUqnRiK1Gon5Z7BXEWFHOTP:iPN7i4MyGbst+KJh465Z7BXrFuTP
TLSH CBC2F116AC33C2595638CDB61EC5D2CD6618BE0CCFBB390C9646EEE73992414CE820F2
Reporter abuse_ch
Tags:COVID-19 GuLoader z


Avatar
abuse_ch
COVID-19 themed malspam distributing GuLoader:

HELO: lamco.ae
Sending IP: 209.58.149.65
From: Shabeer M. T. <shabeert@lamco.ae>
Subject: Payment Assistance Due To Covid-19 Pandemic
Attachment: Payment Advice Note from 0324098457.pdf.z (contains "Payment Advice Note from 0324098457.exe")

HELO: h2.domains.sb
Sending IP: 52.10.241.220
From: Shabeer <shabeert@lamco.ae>
Subject: Payment Assistance Due To Covid-19 Pandemic
Attachment: Payment Advice Note from 0324098457.pdf.z (contains "Payment Advice Note from 0324098457.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1x4QIaEIYJueFynpzhwtnkaCxNkLmm3B0

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-02 04:35:47 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
17 of 47 (36.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

z a99ab2e8d5db3ced555cb7968881064f418c90133b3e3af5a2beb3befb79f21c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments