MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f698def74a7c9cf8da55c527484a139df75baa5d1f71ac305bec51631b633266. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f698def74a7c9cf8da55c527484a139df75baa5d1f71ac305bec51631b633266
SHA3-384 hash: f6b2340e3383d2806ca9f112f33b7b00263a18ada3af450f269b9b42380bcb3e14e8796cc94178a519afdae85b3f0215
SHA1 hash: 81342809cd1931320226a8b18cb8a238099ec945
MD5 hash: e9284f360b9b0a5f7b7cff65ef73babf
humanhash: beryllium-triple-oven-oven
File name:file.jpeg.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2020-05-21 08:49:44 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 768:G7rWcBI3zG3BTdCbjBdclY/LjYPDgSX5H0RhEpDthWTel:G2sJ8BKlSLjYPDg65HWiZWTo
TLSH B3450860F6909D61C5D487FE6E54CB6891ABAC341521CA0B3ADE3F1D0BF6B91AC2074B
Reporter abuse_ch
Tags:GuLoader img


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail2.prosyst.com.br
Sending IP: 177.204.19.137
From: 销售经理 <diego.zapella@prosyst.com.br>
Subject: 要求报价和价格N95 / FFP2
Attachment: file.jpeg.img (contains "Quotation.exe")

GuLoader payload URL:
http://45.132.241.148/tt/bin_yjlzNiXBnc226.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 07:52:37 UTC
AV detection:
12 of 30 (40.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img f698def74a7c9cf8da55c527484a139df75baa5d1f71ac305bec51631b633266

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments