MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db29a893a3667c27113dddb42090c281b7916f3e42945f5280241969ede2d072. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: db29a893a3667c27113dddb42090c281b7916f3e42945f5280241969ede2d072
SHA3-384 hash: 9e539fa846d8d69d5ace5f54cd737a0d9b846e051390ae552f30cd6a61d309a401895af895bf2b61ba2ae9a1b9c96844
SHA1 hash: 22c41a34659c712faa75457a8ae528e0e2287d43
MD5 hash: 448a73fb9b19904cfa2664db555d81a6
humanhash: grey-queen-paris-lima
File name:REVISION OF INITIAL QUOTATION.zip
Download: download sample
Signature GuLoader
File size:30'004 bytes
First seen:2020-05-26 07:24:11 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:nY4OvyF2WUpwMcHToKTjyQIh5M/yldE4dX6NM9Q:GvE5kwMcHMsfIh5DEqKNd
TLSH 07D2F18658D05C90E70744B5F8EBA7CA2F14D68E9CA80C5CA24DA99E71CDE1F5DF800F
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: binhdonghung.com.vn
Sending IP: 156.96.62.50
From: Purchase Manager<kimgiac@binhdonghung.com.vn>
Reply-To: Sophiaxu01@gmail.com
Subject: REVISION OF INITIAL QUOTATION
Attachment: REVISION OF INITIAL QUOTATION.zip (contains "REVISION OF INITIAL QUOTATION.exe")

GuLoader payload URL:
http://hosseinsoltani.ir/legacy_hwYFIzpwb106.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-05-26 07:36:33 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
23 of 48 (47.92%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip db29a893a3667c27113dddb42090c281b7916f3e42945f5280241969ede2d072

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments