MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9c063ae8844fe7913121b3cc6a4ce129496d18b7a54711e194db1939887a0f8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c9c063ae8844fe7913121b3cc6a4ce129496d18b7a54711e194db1939887a0f8
SHA3-384 hash: ed57edce8adc1e51d21721b7206d7a163c167a5a482c22c38d12ba24290935bf9a9a7d8a039fcf345b877a096f9094d6
SHA1 hash: 5896da29b4c150453e1fb3cb050e660b5e607fe3
MD5 hash: ec6dc4f54eec016a0a5d0e9a290a717c
humanhash: mobile-neptune-bluebird-delaware
File name:964309_Invoice_confirmation.iso
Download: download sample
Signature GuLoader
File size:155'648 bytes
First seen:2021-01-08 08:22:14 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 1536:7EqZdfva2ckw6GR81Zsy+wHVVQ5C6eXwoJXxL7:bTva2o68yn7woJF
TLSH 14E3C57FF750F732C75180B45A647E60034A683219399B47F68E261E2B7AAFE8518353
Reporter abuse_ch
Tags:GuLoader iso


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: parfum-bhs.ru
Sending IP: 84.42.40.54
From: Jerry David <nataly1@parfum-bhs.ru>
Subject: Payment Confirmation..
Attachment: 964309_Invoice_confirmation.iso (contains "964309_Invoice_confirmation.exe")

GuLoader payload URL:
https://newsnowextra.com/jk/janomo_EJIMHXJx176.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
186
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Infostealer.Generic
Status:
Suspicious
First seen:
2021-01-08 08:23:12 UTC
AV detection:
9 of 46 (19.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso c9c063ae8844fe7913121b3cc6a4ce129496d18b7a54711e194db1939887a0f8

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments