MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bc02ab76fdd71c94a6ab6e11b8d568c94fce0888cebfff2e151ecbc29ba5b31b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bc02ab76fdd71c94a6ab6e11b8d568c94fce0888cebfff2e151ecbc29ba5b31b
SHA3-384 hash: 2959e1e911d4bd78a91ecc2395f42ed58a9c40a7223f95ec9ae71368afe60bae50ebf2289dbb34f9f01bacf77659bdfa
SHA1 hash: 8f89a943a8f239d7b5f6bcc26ccb5c3a1487cfbd
MD5 hash: 4a689aca594442579079cf41b5c33667
humanhash: september-sad-october-mountain
File name:XINYI ENERGY P2.arj
Download: download sample
Signature GuLoader
File size:32'535 bytes
First seen:2020-06-10 17:28:59 UTC
Last seen:Never
File type: arj
MIME type:application/x-rar
ssdeep 768:PXkckgxIq1lo50KjiSJVJeuey7UAep/cCzk6srR2msWHIL:PXlxb1lzKjiWLSSCg6WRgL
TLSH 83E2E127F23997BE934021220DE1570103735DA2655A88AE7ADFFA5225330BFCFA7395
Reporter abuse_ch
Tags:arj GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

From: XINYI ENERGY <info@huttextechnologies.solutions>
Subject: RE:Subject:XINYI ENERGY New Enquire+S-2078603 and Acessories
Attachment: XINYI ENERGY P2.arj (contains "XINYI ENERGY P2.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=2C38C37ED8430789&resid=2C38C37ED8430789%21115&authkey=AGLzNnSx71tBe9E

Intelligence


File Origin
# of uploads :
1
# of downloads :
131
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-10 17:30:15 UTC
AV detection:
15 of 31 (48.39%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

arj bc02ab76fdd71c94a6ab6e11b8d568c94fce0888cebfff2e151ecbc29ba5b31b

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments