MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c86eecebad683796df13e2ca9d95a2cacbdb9f149ba388cb1e0af9b590dccda4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: c86eecebad683796df13e2ca9d95a2cacbdb9f149ba388cb1e0af9b590dccda4
SHA3-384 hash: fe7453f407504816fb119d9ff75e4f816aec01956b78877d6bfd114ec3d2bf4169a861fa4f2f5f8ab1bd08ed77122f6b
SHA1 hash: e77e25b211120f7e6605f1c93b02b55094cafb10
MD5 hash: 567d30ff7b55c5ce7a29ded374423fa7
humanhash: sierra-mars-timing-louisiana
File name:Daiho_Sea_Air_Invoice_pdf.gz
Download: download sample
Signature GuLoader
File size:44'784 bytes
First seen:2020-06-05 13:36:59 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:fryWKJhuLyQX8gLwewOsPUHGC9J3cgsUvwAGIFg8mWRhdx0F2Dps5Ep045DMXVLl:eWQu78VeZDGLUvmgmWjWGi45DQVLcS
TLSH 2013F15102255B2EE1309F1093B5DE7AFCE1C20D25974BCF159B82B36C60C2A99F26BE
Reporter abuse_ch
Tags:GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: novo.com
Sending IP: 83.166.243.90
From: Lee Si-eun <lee.hoh@daihosea.co.kr>
Subject: FW: Daiho - Please Confirm PI
Attachment: Daiho_Sea_Air_Invoice_pdf.gz (contains "Daiho_Sea_Air_Invoice_pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1imMZwz4HguPdbDq4__E19bbPfL46ZNpn

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-05 08:33:49 UTC
AV detection:
20 of 26 (76.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip c86eecebad683796df13e2ca9d95a2cacbdb9f149ba388cb1e0af9b590dccda4

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments