MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0a01d5794f3013a90d21bc8b497908f06495650e9c954c973b2f7e20eb30a12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f0a01d5794f3013a90d21bc8b497908f06495650e9c954c973b2f7e20eb30a12
SHA3-384 hash: 26aacf6fd2d13097bf3153ef5d5dcee4a66a7fd15701a76cafae1aa142dbada2bbdd5ef741f25ac57e7315067bbcbe2b
SHA1 hash: 56feb4bd217a6e45327023c9f3112fc69f40b337
MD5 hash: 09e69ce9ffb5bf401ab3f609505ecdde
humanhash: fish-pasta-white-kilo
File name:HSBC_PAYMENT_ADVICE.arj
Download: download sample
Signature GuLoader
File size:45'304 bytes
First seen:2020-06-08 12:05:27 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:sNs0XY/qIYBR4QMrNqMeOMLHNWg3Mbkcvoi4hJMIAxrEj4t8LvMAy5laYsMosmW3:sNs0XYyLo41Ou+dvR4hX+roKEYsMh3
TLSH 3A13F18E602F2410C2D5A3DC8CAEA4D724F11E85CAA93129FA5B97EB37631D19A1F153
Reporter abuse_ch
Tags:arj GuLoader HSBC


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.neoit.es
Sending IP: 51.178.91.132
From: HSBC Advising Service <advising.service.2117820.754500.2372623210@mail.hsbcnet.hsbc.com>
Subject: Payment Advice - Advice Ref:[GLV802192175] / ACH credits / Customer Ref:[GR2019000643] / Second Party Ref:[557072H]
Attachment: HSBC_PAYMENT_ADVICE.arj (contains "hsbc_payment_advice.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1QL3ZhjFGG7hZD6ykzJicFfQH-Fxc-U96

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 12:07:09 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f0a01d5794f3013a90d21bc8b497908f06495650e9c954c973b2f7e20eb30a12

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments