MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f46181392bec690c0625236f7de0ee27635779dfb77a68c3e3255712289f76be. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GuLoader
Vendor detections: 4
| SHA256 hash: | f46181392bec690c0625236f7de0ee27635779dfb77a68c3e3255712289f76be |
|---|---|
| SHA3-384 hash: | f3c2fc94312e804cbbbfca5a6dff60f7c886cee13e113bd21c8c2f1c79290dd935f7f47726795349eb6e39f31f97d9c2 |
| SHA1 hash: | c24176fb620cf96fe5a826c9bc9a7234958b7ae1 |
| MD5 hash: | f4d71c33894812a4cc71974cf3a68bdb |
| humanhash: | mobile-eight-white-yankee |
| File name: | 001982_Invoice_confirmation.iso |
| Download: | download sample |
| Signature | GuLoader |
| File size: | 151'552 bytes |
| First seen: | 2021-01-08 19:06:04 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 1536:0+XxmD5xOJi1Hz9EH9WFaqW/k2Vu48dL:0Cyzgo5Exuv |
| TLSH | A2E3E87EB260EBB2C61680F12A107F64039668311939DB87F1DD270E77BA9FE9524743 |
| Reporter | |
| Tags: | GuLoader iso |
abuse_ch
Malspam distributing GuLoader:HELO: mail.winpal.net
Sending IP: 210.225.196.133
From: Jerry David <fang@com.hk>
Subject: Payment Confirmation.
Attachment: 001982_Invoice_confirmation.iso (contains "001982_Invoice_confirmation.exe")
GuLoader payload URL:
https://dailyhintnews.com.ng/cam/janomo_cPyVBFEjnd226.bin
Intelligence
File Origin
# of uploads :
1
# of downloads :
368
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
MALICIOUS
Threat name:
Win32.Malware.Generic
Status:
Suspicious
First seen:
2021-01-08 19:06:09 UTC
AV detection:
6 of 46 (13.04%)
Threat level:
2/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
GuLoader
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.