MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e6e85c7dee15e68872a6579cc8af8c01662316db6f6af8132ef178c643d66881. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e6e85c7dee15e68872a6579cc8af8c01662316db6f6af8132ef178c643d66881
SHA3-384 hash: 8f60b2f8dd827ef062fce1b3720ff369a4c1c85748c13e7f5c7c4c631c60d69905ac414027cec03a7da58b94f87af1af
SHA1 hash: e3013c6285cfea41e31dbafad4c0f86102b4c310
MD5 hash: a2cee25ff6fe14d72c888e5ad2e834ca
humanhash: robert-william-iowa-butter
File name:prijavnica za preventivno opremo·pdf.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-06-02 11:12:25 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c8e40cfeb26871555a8a91c6fc569218 (6 x GuLoader)
ssdeep 768:c8hc7416N8lBR2zL6wfXD9wpogrvOLD8bFGVaB9b2+oWGefY93ao:BFO8lL2RwLrv6GBLTGef4
Threatray 901 similar samples on MalwareBazaar
TLSH 30734B0BAD088E51C57086711D67C7AE3F15BC0C49866E8F784E7E57BB323626C9E21D
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: cpanel.geoenergetika.serv.si
Sending IP: 195.144.26.50
From: slovenski nacionalni inštitut za zdravje <katarina.Vojvodic@nijz.si>
Reply-To: katarina.Vojvodic@nijz.si
Subject: Distribucija zaščitne opreme Covid-19 (Ministrstvo za zdravje Slovenija) Junij 2020
Attachment: prijavnica za preventivno opremo·pdf.zip (contains "prijavnica za preventivno opremo·pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1M_uKXeeoDhkvQQbqrL-NBkPMU2YX-PI6

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 10:49:03 UTC
AV detection:
24 of 48 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe e6e85c7dee15e68872a6579cc8af8c01662316db6f6af8132ef178c643d66881

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments