MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f34ad31573b481dc15737e7b8af94021f1a5bb7ce2fed148eb435910cdfd06a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f34ad31573b481dc15737e7b8af94021f1a5bb7ce2fed148eb435910cdfd06a1
SHA3-384 hash: 35622761cf81a37d019264af1c2d892564c87ca00dd8f3be26e1dda007e5802a0aa17223c8f06b355f5fa136251817a6
SHA1 hash: b70bf01f6841ae4a8d5e42c56f6da4fce79ebd39
MD5 hash: 7cc21f6e3f521e8c942dd2b396da6dfb
humanhash: uncle-kilo-black-lamp
File name:world health organization proposal file.zip
Download: download sample
Signature GuLoader
File size:35'532 bytes
First seen:2020-06-02 11:09:34 UTC
Last seen:2020-06-02 11:32:32 UTC
File type: zip
MIME type:application/zip
ssdeep 768:yrKxJAuIULhf9g4GP8yh7G8Owk37AF4/AMelchOhVGZ/ymPn7:yrKXAPsfhGP887Gv37a44MeDTlGn7
TLSH 9FF2E223A0CD5353C0C5E023B76D663AC0419C6ED9166C40EB53D1FA6ADAF7253F9725
Reporter abuse_ch
Tags:GuLoader WHO zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: smtpgate04.genotec.ch
Sending IP: 81.221.254.53
From: resourceteam@worldhealth.org
Reply-To: victoria_bannister2009@hotmail.com
Subject: INTENTION FOR EXPRESSION OF INTEREST: WHO/2020/06/02/AA1
Attachment: world health organization proposal file.zip (contains "Atrofierendes4.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1wOlpmTA15MUHYuQiL4QonKzdP6YMl5Hx

Intelligence


File Origin
# of uploads :
2
# of downloads :
75
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-06-02 21:49:15 UTC
AV detection:
22 of 48 (45.83%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f34ad31573b481dc15737e7b8af94021f1a5bb7ce2fed148eb435910cdfd06a1

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments