MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1d5d7b4776c77029c193b77441f43ad2d8c4a27ccec0f48a1dc0e3b54b996d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c1d5d7b4776c77029c193b77441f43ad2d8c4a27ccec0f48a1dc0e3b54b996d5
SHA3-384 hash: 2108153d754b4b68ff1ad2af385a84c83dd5edb0e0bf3ddb97da19ea1cd82665a8a93149fa252274ab692e664e4ac5c3
SHA1 hash: ab7d39374a9037e8e8980dacdb8158aa10f83c8b
MD5 hash: 5c8f8cccbd9cbb2835b6db3dc2393c8f
humanhash: bluebird-london-papa-undress
File name:new order.rar
Download: download sample
Signature GuLoader
File size:28'321 bytes
First seen:2020-05-05 07:49:42 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:8ygeVCoU2wg0yW3XJQUgTdAhzfQVW+GpHfkgP:qeQd2wlJQUqAhzfCjGJfk0
TLSH C7D2E06CCF491520BD8486ECF3E916F82B80094B5637335A03590B65AE368DF67D1EEA
Reporter abuse_ch
Tags:GuLoader Loki rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: pleskl36.axarnet.es
Sending IP: 91.142.210.104
From: Catherine Minio<c.mini@blancmariclo.com>
Reply-To: <c.mini@blancmariclo.com>
Subject: Quotation for new order
Attachment: new order.rar (contains "new order.exe")

GuLoader pushing Loki

Loki payload URL:
http://castmart.ga/~zadmin/xcloud/gold_TtBaWDj152.bin

Loki C2:
http://allenservice.ga/~zadmin/lmark/gld/link.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-05 08:36:24 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar c1d5d7b4776c77029c193b77441f43ad2d8c4a27ccec0f48a1dc0e3b54b996d5

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments