MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3c1736f03530cd7e6ed1404ee3a9c1a287c15e09d58b3cc93ed8f0bd91f1947. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: e3c1736f03530cd7e6ed1404ee3a9c1a287c15e09d58b3cc93ed8f0bd91f1947
SHA3-384 hash: 521b71f8cac18bcc1e3f3e6907cb66a5e4dc10e0d01f1de0c226feb16aed33afd0afb85af264415a3de5bd39deb5657e
SHA1 hash: 9584c20b47199987968d18021b465a65ea1df3c5
MD5 hash: 041f16554f9bff087923b433cc3e1381
humanhash: quebec-floor-bulldog-illinois
File name:PI-20-03283.rar
Download: download sample
Signature GuLoader
File size:22'741 bytes
First seen:2021-01-15 07:16:51 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 384:5eYOQHPfnWFU+DUiwHJufpXi1VYZlCgS9s2URKdqhbA3ud6xYUJaw1GrBRjjr:8UHPfnkD9wHJGGVeS9sVhhbA3uGYCL+D
TLSH B6A2E1BDFF138C59F04B9977691ACB1E80A761DC853B4CE2269C406EA1C6E7C2567A20
Reporter abuse_ch
Tags:GuLoader rar


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.epcafrica.com
Sending IP: 41.186.72.34
From: sales@alliancex.com
Subject: New Inquiry / Quotation Request
Attachment: PI-20-03283.rar (contains "(PI-20-03283).exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1Dke_tqEGa6XYQhjHpthS3ctdWi1hsoIU

Intelligence


File Origin
# of uploads :
1
# of downloads :
227
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar e3c1736f03530cd7e6ed1404ee3a9c1a287c15e09d58b3cc93ed8f0bd91f1947

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments