MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e604ad9f0cc6393b1aa5ddca624260615f54f497192c9becac0b2233b05e50ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e604ad9f0cc6393b1aa5ddca624260615f54f497192c9becac0b2233b05e50ae
SHA3-384 hash: 792f1b050b7e0280a6730ed5442911a80d439ad2d80a061680d9118db5283aed32c60a1309cb98907af807ab72148b79
SHA1 hash: 9e6236e593f2cb611e18e0d2a8d5f9227f938412
MD5 hash: d5babbd3505376ebf85de5ab9cd0245a
humanhash: blue-michigan-colorado-oranges
File name:consignment invoice·pdf.zip
Download: download sample
Signature GuLoader
File size:35'896 bytes
First seen:2020-06-02 11:15:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:+g9L/kXekPH/j2yQm/u4nslnGSP3WMT5JIM2+r33tfOHsWkvSdEFqIPrqr:+g9TUe8/BQm/ZWVP3tJIM2+r3UHsWYqj
TLSH 24F2F1A9E78DD4C6E5B12F37722370261D22D304E8F9A3801D75435AC6C58BAF2964F7
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: sv1.f5solutions.ro
Sending IP: 185.84.65.209
From: TNT Shipment Notification <shipment@mail.tnt.com>
Subject: TNT Consignment Notification for 243740512
Attachment: consignment invoice·pdf.zip (contains "consignment invoice·pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1D5PjbN9HnUCh7an9YFSMXn5eyJ7Nh0DA

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-03 04:02:26 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip e604ad9f0cc6393b1aa5ddca624260615f54f497192c9becac0b2233b05e50ae

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments