MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c374f75d17d6b5f497d2d57ce5e39be48434638a2e6cb0d995dd8a325f5db102. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c374f75d17d6b5f497d2d57ce5e39be48434638a2e6cb0d995dd8a325f5db102
SHA3-384 hash: c2c390cf004e09642372886a04675b00d3a1f66840e4b0d264f833dd5faf3b38917e06b9b44c42264aed57644102a2f8
SHA1 hash: 68a93ede728fe7d67723d9734a10f0c7f2b007a4
MD5 hash: cc180c52d1a9a7c50fba09e5d039f2d7
humanhash: nitrogen-muppet-king-failed
File name:Attachments.zip
Download: download sample
Signature GuLoader
File size:45'415 bytes
First seen:2020-06-08 12:05:38 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:X7mN57jNMFJP/QfFQJSPMhWn+g0/9Z2pSeY9EcGfbezX0+bca2Q4zGc5dfaUzHZN:LmN57jUJHQfpMwT0HISemEcGKzX0GDCT
TLSH 4813E1C91447C7B0D0BAB1C3BE0556C257EB25D66ACE13F426607402162FC5DEEF5E94
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mana1.bbconstruction.online
Sending IP: 104.168.170.170
From: Mary Ann <contact@bbconstruction.online>
Reply-To: Mary Ann <ann956844@gmail.com>
Subject: RE: Payment Update
Attachment: Attachments.zip (contains "MT103SWIFT002.pif")

GuLoader payload URL:
https://drive.google.com/uc?/export=download&id=1ZcuTWiAVMvQJ6KV3-eomkgJbWSflc00H

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-08 12:07:11 UTC
AV detection:
26 of 48 (54.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip c374f75d17d6b5f497d2d57ce5e39be48434638a2e6cb0d995dd8a325f5db102

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments