MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cec48db9ac62885f0543b3bed752b43d62d41e89face0accc085660e81ba5079. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: cec48db9ac62885f0543b3bed752b43d62d41e89face0accc085660e81ba5079
SHA3-384 hash: 93803e720c739582bb89c67a35b9aa16384c5e08679dcabfe585be845ae2fc22f51e1bc47dc7bc5a83d1e88ab75648dc
SHA1 hash: 322b90bee10bb37ece1a5e419c2f625e08779f1d
MD5 hash: 20326a7f6966cd59d980ce2691477412
humanhash: coffee-five-stairway-enemy
File name:Templates_RoHS_Rev.zip
Download: download sample
Signature GuLoader
File size:43'752 bytes
First seen:2020-07-31 07:11:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:iWPSPxY71x71lK5UD1XGYje/6glikqo/9d70zd2UsJwRvWJvNC6zL61Ihmrd5D:i3Pxk9bhlepikP/9bJwlWJvVzWZrd5
TLSH 9D13F16638AE7D16ED0B3AF062ED77A47690D417FF42987345C553CBF23890378049AA
Reporter abuse_ch
Tags:AveMariaRAT GuLoader RAT zip


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: vps.hond-red.xyz
Sending IP: 45.95.169.93
From: info@hond-red.xyz
Reply-To: info@hond-red.xyz
Subject: Quote#CON-071720-EB
Attachment: Templates_RoHS_Rev.zip (contains "BV10013 (Rev A).scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
112
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-07-31 07:12:16 UTC
AV detection:
34 of 48 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip cec48db9ac62885f0543b3bed752b43d62d41e89face0accc085660e81ba5079

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments