MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb939efc95b45c09f4d3599c0d19051ac901ed2568823163517ef5a0f6b2b13a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bb939efc95b45c09f4d3599c0d19051ac901ed2568823163517ef5a0f6b2b13a
SHA3-384 hash: 4351e0a9630eb885d7ebb59fd71b731ed5be4b5333fa74abaffb3da09c90e54ce1469da1bbe183559c0315fe0c8c31c8
SHA1 hash: a17402ef2d9d58d212baa482e1f60306357b3469
MD5 hash: 0d8931dcf3fc70273ccf0b90561a9988
humanhash: emma-utah-red-quebec
File name:E-Invoicing No.70015232_pdf.gz
Download: download sample
Signature GuLoader
File size:72'910 bytes
First seen:2020-06-03 13:03:18 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 1536:3GBJro79+JbQnhbb/m9vU30kZ9R5AnOaVG332rY5vZkmr:3mJro79SbQNb/hPt52OErIvZk6
TLSH 8E6302C2FEA6851FAAEF1A48D87AB123374501820177A331C0B7AA4B17C552FF694D6D
Reporter abuse_ch
Tags:GuLoader gz Maersk


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.abidjiaintl.ml
Sending IP: 155.94.211.87
From: MAERSK SEALAND - INVOICING SYSTEM <casy@abidjiaintl.ml>
Subject: Maersk Sealand Container Invoice No : 70015232 Bank Virtual Acc No : 9868 000127604
Attachment: E-Invoicing No.70015232_pdf.gz (contains "E-Invoicing No.70015232_pdf.exe")

GuLoader payload URL:
https://cmdtech.com.vn/build__ol_OrFUVF212.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-03 12:01:25 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
21 of 48 (43.75%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz bb939efc95b45c09f4d3599c0d19051ac901ed2568823163517ef5a0f6b2b13a

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments