MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8c1ec4cfbbc1679ebde1fe54ae9072f55c3b5fcaaa2cba8791b675c6c59bcc4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e8c1ec4cfbbc1679ebde1fe54ae9072f55c3b5fcaaa2cba8791b675c6c59bcc4
SHA3-384 hash: 0481116999c4ee7c76add111dade4cd4997e3728d8f5538d7fef5cde980637060ed0c7059833eaa86739b696b8144db2
SHA1 hash: ebffb8c35e92baca1275b2dd3983f7eed2d8a559
MD5 hash: 8adc266bb082dd867f74ea087528b0b1
humanhash: october-fillet-purple-berlin
File name:Thai June France Urgent Order.gz
Download: download sample
Signature GuLoader
File size:21'740 bytes
First seen:2020-06-08 12:14:28 UTC
Last seen:Never
File type: gz
MIME type:application/gzip
ssdeep 384:CawEadKQR4HHd3PT+kOK2g/u/3h/VkCWqUfA8p4V81ugNY4XYfA4aWtfY8xK:CaJFQaHMVTfh/Vlp82uY4ooOzxK
TLSH A6A2F15FF90814132692E1DB2B412CDBAD9EBF8E5D5983F46F5AC59E1890884EE00E32
Reporter abuse_ch
Tags:geo GuLoader gz THA


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: clean302.mxserver.ro
Sending IP: 176.223.125.222
From: Jordan Tyrban <jordan@lalemant-france.fr>
Subject: จำเป็นต้องมีใบเสนอราคาด่วนสำหรับฝรั่งเศส
Attachment: Thai June France Urgent Order.gz (contains "gunzipped")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1dh61IWa7fEtgrnP8A53Q04fHssd8qOWY

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 12:16:07 UTC
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

gz e8c1ec4cfbbc1679ebde1fe54ae9072f55c3b5fcaaa2cba8791b675c6c59bcc4

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments