MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ca9e0ac7f29ab0a7a68110f7d563b116984c1df926ab2d9252e5c30198fefb75. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ca9e0ac7f29ab0a7a68110f7d563b116984c1df926ab2d9252e5c30198fefb75
SHA3-384 hash: 8027cef461c414588fd84aadb13af5dd35cd3316958854ca24775f3bf12f6ec78d7c2d2dffd2028382d1db346dee0f05
SHA1 hash: 4d14a0e7f1f1199852ea7181fc4b3e191ae9d0db
MD5 hash: ccb13b648c4192d8e8eb53b791fb2dac
humanhash: undress-speaker-alanine-nitrogen
File name:DHL Consignment Details-pdf.gz
Download: download sample
Signature GuLoader
File size:75'739 bytes
First seen:2020-06-04 06:04:13 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 1536:RZB26KnmSUeN0El1ACY8glBdG9mLZc7T+kewK3XVAeU/lHYGO7TDJmvd:7B26Knjl1/YLTL+h1K3lACjJE
TLSH 6973023C61501249D3246B5940AFBDADB397AC2691BB839C09FCADC1A839ECC1557E73
Reporter abuse_ch
Tags:DHL GuLoader gz


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail0.470.celumltd.casa
Sending IP: 128.199.192.91
From: DHL DELIVERY REPORT <dhl@470.celumltd.casa>
Subject: DHL Delivery
Attachment: DHL Consignment Details-pdf.gz (contains "DHL Consignment Details-pdf.exe")

GuLoader payload URL:
https://automarsel.pl/2ND_OhXwqURK78.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-04 06:37:55 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz ca9e0ac7f29ab0a7a68110f7d563b116984c1df926ab2d9252e5c30198fefb75

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments