MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ce13b6969219a3acc2cd23208f987f4a2f6779b6bd34bfc22c6f35946cf2fad7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 1 File information 3 Yara Comments

SHA256 hash: ce13b6969219a3acc2cd23208f987f4a2f6779b6bd34bfc22c6f35946cf2fad7
SHA1 hash: 75f961ce9a4e66fc5e4a1171a2f20fd75cf21bf8
MD5 hash: c81999ecbf702c3071b1a6abe3c6a1aa
File name:Order#2256215M_pdf.exe
Download: download sample
Signature GuLoader
File size:90'112 bytes
First seen:2020-05-22 15:03:26 UTC
Last seen:2020-05-22 15:48:44 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5b0da6c1de945a710ef5ef13e4b8e91c
ssdeep 768:6ByGGf1TZySoO//YsIz2Y5cU/Gg74WN7WswjpO0kMwoX24vQrRItu3cpnroSR:kK9TZjv/XA26B74oWsMpO0Go7Tnrl
TLSH 43933B157DA8ECB2CC104EB55D26D59412EBBD313D4A8F0F388A3B1C3A775F26A16326
Reporter @abuse_ch
Tags:exe GuLoader


Twitter
@abuse_ch
Malspam distributing GuLoader:

HELO: qq.com
Sending IP: 183.3.255.184
From: Sales <reservations@ss-wq.com>
Reply-To: pay@sh-soa.com
Subject: New Order (Urgent)
Attachment: Order2256215M_pdf.zip (contains "Order#2256215M_pdf.exe")

Intelligence


Mail intelligence
Trap location Impact
Global Low
# of uploads 2
# of downloads 28
Origin country US US
ClamAV SecuriteInfo.com.Variant.Ursu.878098.20061.25433.UNOFFICIAL
VirusTotal:Virustotal results 33.80%
ReversingLabs :No data

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe ce13b6969219a3acc2cd23208f987f4a2f6779b6bd34bfc22c6f35946cf2fad7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments