MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bda0bad16ddc0185ec8ff422e9e74c5f526993ea439f6f3da242e21ade712e98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bda0bad16ddc0185ec8ff422e9e74c5f526993ea439f6f3da242e21ade712e98
SHA3-384 hash: ef5eac7ca8abd23b1ad311d807eb241b70b61158b45ab76bc30698815fdb8abfa22714af77521efb3d79ad78f608268a
SHA1 hash: 411eee4d118a2b21d886592220698c6bc22cd314
MD5 hash: 2cde13dcfd40676e54eb265ebee26316
humanhash: fifteen-oscar-social-alabama
File name:ekstre_04-08-2020.iso
Download: download sample
Signature GuLoader
File size:163'840 bytes
First seen:2020-08-04 15:22:40 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 768:8g1JflGmz9dwkuGcUQRyjQOZ8uTMXCzmq8Ukt2c2P/Q7s+7RFJ:f1dl/yRyjQgPXmqTktnuiRF
TLSH 24F3D616A5A44239F267DB714DB456F7017EBC38383E898B7DEC395A37B3A048610B27
Reporter abuse_ch
Tags:geo GuLoader iso TUR ZiraatBank


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: neo.composeit.hu
Sending IP: 185.51.67.119
From: ZIRAAT BANKASI <zb.ekstria@ileti.ziraatbank.com.tr>
Subject: T.C. Ziraat Bankasi Hesap Ekstresi
Attachment: ekstre_04-08-2020.iso (contains "ekstre_04-08-2020.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1eKHAR39_MoPcZq3VOS2AFZ752tgRSw4I

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-08-04 15:24:09 UTC
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso bda0bad16ddc0185ec8ff422e9e74c5f526993ea439f6f3da242e21ade712e98

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments