MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c6ee30c1f69180397dddceec5a089f83397a0edebbf27164ee5763b9a1221158. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: c6ee30c1f69180397dddceec5a089f83397a0edebbf27164ee5763b9a1221158
SHA3-384 hash: 86bb25fc73b985576990eccb25b38f16e311beb732943d8039e90c4d908b155fbb8e2de8e6823eae78f082f415458b09
SHA1 hash: f96be6c1c5678712e127e1bcef463c944eeff19e
MD5 hash: 6beae0e96820fbdbaf81cd5909242db2
humanhash: april-social-south-oven
File name:707-6-2_PDF.zip
Download: download sample
Signature GuLoader
File size:50'324 bytes
First seen:2020-06-07 14:25:13 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:cMspZctXIdQ2rxD3mKqXV4DJZyc7LlWh46UsOw99CE6Ntgx8x0JUk:eFF2Wyc3IzUsOAChZOJv
TLSH 863302B1E642DE6DCE071A4990357A4680D32393232C3878DCD6FC09DA2A36B5B5F83D
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.cyberadvert.co.za
Sending IP: 165.73.140.84
From: info <info@flowerparadise.co.za>
Reply-To: info@flowerparadise.co.za
Subject: RE: BL and Packing List - 100% viscose 2/30 BKC
Attachment: 707-6-2_PDF.zip (contains "707-6-2_PDF.com")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1gErWJxr281t3lIf6qZgihMFkVPbx10NG

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip c6ee30c1f69180397dddceec5a089f83397a0edebbf27164ee5763b9a1221158

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments