MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f6b6e6952da86504cff67b9b8fd6eb94a52e239e83707086ad9df8992ca6677c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f6b6e6952da86504cff67b9b8fd6eb94a52e239e83707086ad9df8992ca6677c
SHA3-384 hash: 1fc6c51f926f119a5192d1a705f61dac7e897e29ce8ed00a8317ec63a70d3072f1a445009bff65890e6d99affbc308be
SHA1 hash: 0ab7d9045c669f1e85bed31ff435833bb8a67a47
MD5 hash: 132eaac12c8488557c86787d2b0dab65
humanhash: sweet-zulu-diet-saturn
File name:Detalhes da remessa 28-05-2020.pdf
Download: download sample
Signature GuLoader
File size:58'931 bytes
First seen:2020-05-28 13:15:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:RPw0JV/LO+BYaRirEaFMJ9fnQ3bPQCGlbl8KbAB:R40JlBZw2fobPWlblZ8B
TLSH A943F1D87B7338D141B3A464D9ACE32B8527A821A13B7A725DCFE2DE05583B270A5743
Reporter abuse_ch
Tags:GuLoader pdf TNT


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: vps.cnidcloud.com
Sending IP: 198.38.86.192
From: TNT Shipment Notification <shipment@mail.tnt.com>
Subject: TNT Consignment Notification for 243740512
Attachment: Detalhes da remessa 28-05-2020.pdf (contains "Detalhes da remessa 28-05-2020.pdf.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1lpaWEQp26aL7dUlhl5YcwNu_PNwSJtfo

Intelligence


File Origin
# of uploads :
1
# of downloads :
155
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Downloader.Doubleext
Status:
Suspicious
First seen:
2020-05-28 13:38:19 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
4 of 48 (8.33%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f6b6e6952da86504cff67b9b8fd6eb94a52e239e83707086ad9df8992ca6677c

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments