MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca8fd71e72554eaf384e8047089c23f51126a541f6c50b0d572ab88579b0df02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ca8fd71e72554eaf384e8047089c23f51126a541f6c50b0d572ab88579b0df02
SHA3-384 hash: f1880407e08fb302156e506babc84e9e5b7809988dff9e763be0a174f8e3fe62d030d49a7e47e4f9c548aa28cad13c37
SHA1 hash: b9c81df6292d4ed736cf5213c3a71d6630455444
MD5 hash: 1a5dfa63d076b85ce447278c040bdc11
humanhash: florida-whiskey-undress-glucose
File name:WHP03-PMC1-101-P20608-0001.rar
Download: download sample
Signature GuLoader
File size:41'161 bytes
First seen:2020-06-09 05:45:49 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:E2+5P6vuzaotGXZsgO+61CAks4lp/3kKQDtxZyVxikXcL5/GQ5:gip0GJTP6Hhw/3Z0dr5
TLSH A50302BFB2ABA9884C8C02A90F29F3B49C0CF3C465A9FF4159329D94F5D1A1581BD754
Reporter abuse_ch
Tags:geo GuLoader rar VNM


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: viettelidc.com.vn
Sending IP: 103.1.208.206
From: Nguyễn Ngọc Diễm Quỳnh - EBVN [ngoc.nguyen@vn.eagleburgmann.com] <hanhhh@kmg.vn>
Subject: RE: Inquiry from EBVN - RFQ # 20608-0001 Ref. WHP03 Project Hanoi VN
Attachment: WHP03-PMC1-101-P20608-0001.rar (contains "WHP01-PMC1-101-P20608-0001.exe")

GuLoader payload URL:
http://ratamodu.ga/~zadmin/group/harl_cyMbNbo109.bin

Loki C2:
http://egamcorps.ga/~zadmin/lmark/harley/mode.php

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-09 05:47:06 UTC
AV detection:
7 of 48 (14.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar ca8fd71e72554eaf384e8047089c23f51126a541f6c50b0d572ab88579b0df02

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments