MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f711fa297376546566c11eade3a0de2344ee0d9eb74ccb42ab4575751bb50b2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f711fa297376546566c11eade3a0de2344ee0d9eb74ccb42ab4575751bb50b2d
SHA3-384 hash: 678d8c777abf7866ebb949465b8c0972dc8a55e9204db01ee70e8921a655f4bbb090287ea916bee66c39ae459aec209e
SHA1 hash: cd7d4f3918a2148ebfc0afd09285a0a92541241c
MD5 hash: 6bf08d089f16f1b79ed50a96ee4ef433
humanhash: alabama-oxygen-football-iowa
File name:10-06.zip
Download: download sample
Signature GuLoader
File size:33'083 bytes
First seen:2020-06-10 11:39:52 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:zoTS9eQsmIy4WlbxtbxnAfb9vyT83oTFef0C:ddIynllt5AfRjoTF6/
TLSH 07E2F15101F8F29FEA135019B6DA02558A0FAF009073F98D726A7A243FCAC2FF9D5559
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: slot0.maleceez.com
Sending IP: 45.95.169.79
From: Account <info@maleceez.com>
Reply-To: Account <mailreply01@mail.com>
Subject: Fwd: BANK IN SLIP
Attachment: 10-06.zip (contains "10-06.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=17Bfcf2pc8Ku0Iyqhif1OmpIL0W6clwUB

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-06-10 11:41:07 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f711fa297376546566c11eade3a0de2344ee0d9eb74ccb42ab4575751bb50b2d

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments