MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d82b898e223a9fee10367b2b329ff03e1bc2bc96acf15bf43038e59abf834cde. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: d82b898e223a9fee10367b2b329ff03e1bc2bc96acf15bf43038e59abf834cde
SHA3-384 hash: ac70264f7878be1d56deda59dde3143de91979f6c6a27eacb8a62f185faf519f3c0e32e0d7e6fd66e885984b9a0ddbc5
SHA1 hash: 558d9a2fbc667e80688e4b128f495d57b610a48f
MD5 hash: aaa62c27edffcbeec92040dcc3bc29c9
humanhash: nitrogen-beryllium-alabama-tango
File name:ORDER INVOICE.rar
Download: download sample
Signature GuLoader
File size:25'258 bytes
First seen:2020-06-01 08:26:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:w8ke1SsU7QguXCv2cmyIHTIDqLqvHUQSPozUHrZG83KP6WuGLhxQjyrbWmaaaCcz:w85LC9mTCPoPoAHNn6dNL4jy7eP
TLSH B8B2D0245E2E83E7817CA3FF0691A712FB08B45E52599CCE17D4E2FBAC529D076B1124
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

From: "Sales Engineer" <user@t-online.de>
Subject: Re:picture of goods we will like to order from you.
Attachment: ORDER INVOICE.rar (contains "ORDER & INVOICE.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1ruj4EfLfnmtjm6oXOGEowWHp-7QWPElt

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-01 08:36:42 UTC
AV detection:
21 of 48 (43.75%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar d82b898e223a9fee10367b2b329ff03e1bc2bc96acf15bf43038e59abf834cde

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments