MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb6da2e25ac235cedd2abe341b601a2f1c66b6324594bf00d57209aba097d197. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: cb6da2e25ac235cedd2abe341b601a2f1c66b6324594bf00d57209aba097d197
SHA3-384 hash: a30a24929c508415f6f2520b722ad09cf1208c25351bc4bcf855189268968f4842066adbba9e8b4aeed80cfc8f7df04d
SHA1 hash: 94eccf78c4ccdf5a32aa28324a89214770493bbb
MD5 hash: 91fde186405fc48cd20099464d533d86
humanhash: maryland-diet-mockingbird-lactose
File name:New_000098899.xls.z
Download: download sample
Signature GuLoader
File size:23'928 bytes
First seen:2020-05-20 12:24:11 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 384:8mL2GSCjLo8WWnONqammb0V4OrKANJNZ2RgmsmHy2IADCU3MrZFc4wfYvICsGaE2:vXzocNV4SKIJNZggyf9CyfY12
TLSH 01B2E14566A7CEE258B08E469D1C68A6F7E57222081E5FF877010F606777608FD0FB22
Reporter abuse_ch
Tags:GuLoader z


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: slot0.aspaityl.com
Sending IP: 45.95.169.151
From: Satheesh M <ptr.strelnik@mail.ru>
Subject: Order confirmation
Attachment: New_000098899.xls.z (contains "New_000098899.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-20 12:37:43 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
18 of 48 (37.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

z cb6da2e25ac235cedd2abe341b601a2f1c66b6324594bf00d57209aba097d197

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments