MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad5f57bbd5929d65d1ead9f9caa24a406be0e55bf00f59805dda760c7b24552e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ad5f57bbd5929d65d1ead9f9caa24a406be0e55bf00f59805dda760c7b24552e
SHA3-384 hash: 829fc65e4349d4ae12fcea40bff25ff414a3342b0cb4f1c0b9bcf83926c147786824ede288de989983b1214000ee2b20
SHA1 hash: 176c2ed7e0e49a85e1c1920155b2a464cb2bfcc7
MD5 hash: 934057e3d6adda3ca48487d1b4df64fe
humanhash: october-lima-beer-tango
File name:Order New4247832.zip
Download: download sample
Signature GuLoader
File size:47'567 bytes
First seen:2020-06-08 12:13:58 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:Eb2PQO3NtG3RzXv8RPNNXaobrEZnSdaRUC43nAYvLxAx7Zs9J+yt1V77/XgwEYGt:EyPr3bG04ZSdasXvLc7ZGJ+uV77DELOM
TLSH DC23F28BEE6C01E7AC9F507B054618F5225EA2EF4A04B9371644E2C1B1FF5A56CB0DD3
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: hotmail.com
Sending IP: 156.96.62.50
From: Khaliq Baghel<Khaliq@hotmail.com>
Reply-To: snice7312@gmail.com
Subject: Order New:4247832
Attachment: Order New4247832.zip (contains "Order New4247832.exe")

GuLoader payload URL:
http://mu.gurriontour.com/CHUCKS%20LOGGER_wVwkw202.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-08 12:15:08 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip ad5f57bbd5929d65d1ead9f9caa24a406be0e55bf00f59805dda760c7b24552e

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments