MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f353fb602eb036492ffed49e7f71cf9f27cb06db3e07c316b027c63a5f31b8d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GuLoader
Vendor detections: 3
| SHA256 hash: | f353fb602eb036492ffed49e7f71cf9f27cb06db3e07c316b027c63a5f31b8d8 |
|---|---|
| SHA3-384 hash: | d38602b212f4496910f99ecee49218eb1c2d789b23b9c4904dfb8fd9e1cedc41817214e77bcff8d5b18b7bef2e59170c |
| SHA1 hash: | e1fc30f9d05e99b70644297c749d4590181484b6 |
| MD5 hash: | fff409d3d7ae05b1491e41eedcee2e21 |
| humanhash: | ten-sierra-texas-ink |
| File name: | PDF.PO 4507600698 - Rev 01-PDF.gz |
| Download: | download sample |
| Signature | GuLoader |
| File size: | 26'459 bytes |
| First seen: | 2020-05-20 08:43:33 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/gzip |
| ssdeep | 768:Z6p5sMdnDV2I2PGx4+tmqeZRshTQqePiuZVa:ZOr2PGaCHpQqtQI |
| TLSH | DBC2E152DBCD2EE770F8EDAB03BDF1569FE7813C5009AE2ED0A17B521225D1F5491202 |
| Reporter | |
| Tags: | GuLoader gz |
abuse_ch
Malspam distributing unidentified malware:HELO: mail0.82.igfxinvest.com
Sending IP: 68.183.88.97
From: Kelsey Morrison <kmorrison@82.igfxinvest.com>
Subject: PO # 4507600698 - Rev 01
Attachment: PDF.PO 4507600698 - Rev 01-PDF.gz (contains "gunzipped")
Intelligence
File Origin
# of uploads :
1
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-20 09:36:20 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
14 of 48 (29.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.