MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ceaa099f2a2de97a363ef5f7cd4e42fc5f362113a470db75d69848e24a52b14c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry

Intelligence 1 File information 4 Yara Comments

SHA256 hash: ceaa099f2a2de97a363ef5f7cd4e42fc5f362113a470db75d69848e24a52b14c
SHA1 hash: c6cd6928e4b9986e829fcceb955c4c124188af44
MD5 hash: 82ac82216b9033491690ad8f5d996a8c
File name:Remittance Advice.exe
Download: download sample
Signature GuLoader
File size:90'112 bytes
First seen:2020-05-22 09:50:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 55beb1c00a0460d97f11529fd0e040d5
ssdeep 768:vnrZg4LDEknLWr/Rv46WvzOGMp8Nxrev4Z9zrmV:/rZg4fnY/Rv46Wvz0mB/mV
TLSH FB933D10B568DDE2DE044EF2993389E810BBBD752D540F1738C9B79C3B37A459AB131A
Reporter @abuse_ch
Tags:exe GuLoader

Malspam distributing GuLoader:

Sending IP:
Subject: Kindly confirm tt payment made to you today 05/21/2020
Attachment: Remittance Advice.arj (contains "Remittance Advice.exe")

GuLoader payload URL:


Mail intelligence
Trap location Impact
Global Low
# of uploads 1
# of downloads 21
Origin country FR FR
ClamAV No detection
VirusTotal:Virustotal results 8.33%
ReversingLabs :No data

File information

The table below shows additional information about this malware sample such as delivery method and external references.



Executable exe ceaa099f2a2de97a363ef5f7cd4e42fc5f362113a470db75d69848e24a52b14c

(this sample)

Delivery method
Distributed via e-mail attachment