MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence 1 File information 5 Yara Comments

SHA256 hash: d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027
SHA1 hash: 3e35fe3544a321409bc87825303320bbbd0f38f7
MD5 hash: eb39ca7b20582ca5620b61b95dc33fa5
File name:DEMURRAGE CLAIM.zip
Download: download sample
Signature GuLoader
File size:24'589 bytes
First seen:2020-05-22 09:55:47 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:dXieDE8zzWQY+PFHaBs2wmZ4is5WiA4NQk/KQnrrlclIFQ9OQgE9spIm4/wlMdUs:AejZtw2Aux/K+lyR9OQg34/wlMd/OdTk
TLSH 35B2E1A891A98E50C0D10BFCEC25628C82159D9F9709285FF3A47CE13F62FAC554669F
Reporter @abuse_ch
Tags:GuLoader zip


Twitter
@abuse_ch
Malspam distributing GuLoader:

HELO: whm.mastertindo.com
Sending IP: 103.103.192.221
From: Stan Lee/Lin & Associates, Maritime Law Office <stanlee@lamariti.com.tw>
Subject: RE : URGENT !!! DEMURRAGE CLAIM
Attachment: DEMURRAGE CLAIM.zip (contains "DEMURRAGE CLAIM.exe")

GuLoader payload URL:
https://ny.yummyeliquid.info/mana.bin

Intelligence


Mail intelligence
Trap location Impact
Global High
# of uploads 1
# of downloads 21
Origin country FR FR
ClamAV SecuriteInfo.com.Variant.Ursu.878098.19116.2554.UNOFFICIAL
VirusTotal:Virustotal results 30.77%

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip d358879692850f0a60063c077ca517e5591606c759bbe515241c7dae83bb6027

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments