MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb69da87d70a11478dd89717e603870cd0ad0548efe63009237cf7d278fbaba7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bb69da87d70a11478dd89717e603870cd0ad0548efe63009237cf7d278fbaba7
SHA3-384 hash: 1087da75087d00340151a6c5c861a4e73da4da297d99729c4e8905bcfc3a4a5ad5da911e9ec12d9a2aada2092ba4e6c5
SHA1 hash: c3847c15a589dd8aca0e8d94ef5aa4af3c5c755d
MD5 hash: 0837b4e50bff1908c0f9ee610879b5bc
humanhash: alpha-robin-ack-william
File name:P.O 465 Arrow chemicals_DOC.gz
Download: download sample
Signature GuLoader
File size:23'365 bytes
First seen:2020-05-17 10:02:09 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 384:fk1/GR/QaUO8zY1+EL4cM6GCuHTHgtL7W3sxG+hxgkNjCbE0:fiGGSDYE1M6GHgp7W3sQMsE0
TLSH 00A2E18245B24D2BFBCAD1D39CC5661ED4E24C1ECC619763758A6FD48F12D209419CDE
Reporter cocaman
Tags:GuLoader gz


Avatar
cocaman
Malicious email
From: G. Karpagam <azq@pixelnx.com>
Received: from in.pixelnx.com (in.pixelnx.com [103.90.242.177])
Date: 15 May 2020 02:07:21 +0000
Subject: New Proforma Invoice - Urgent
Attachment: P.O 465 Arrow chemicals_DOC.gz

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-05-16 03:54:24 UTC
File Type:
Binary (Archive)
Extracted files:
3
AV detection:
28 of 47 (59.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz bb69da87d70a11478dd89717e603870cd0ad0548efe63009237cf7d278fbaba7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments