MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f81388c85ae6ec47719aeb51c65974a83a27cc7383b3569ce6a75d8cae6d4b92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: f81388c85ae6ec47719aeb51c65974a83a27cc7383b3569ce6a75d8cae6d4b92
SHA3-384 hash: 9ac2602ff742c84dc377ce2f3caebfae5d8450988c66f1e2a59caadc67cb8aa1b24ba26de43013fcf39cfb1a4e4c11a5
SHA1 hash: cba7f0e8e7eb10a1af0fae4036c07f026b8e315d
MD5 hash: be4d7b3e4411ddb77544d0ede2203138
humanhash: romeo-batman-hamper-mike
File name:2020 06 08.zip
Download: download sample
Signature GuLoader
File size:45'149 bytes
First seen:2020-06-08 09:20:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:4ocfL3Dq/cLjZ5HKCgf671oCG7ftf7hfuw2RbJH4eTyqVuZ83+QwZsGryfhh32S6:4lTCcLj7Y671MLu3RbbT0ZtKhxr6
TLSH 2413F1582A4F69CA51CD5625E3078A1092BD6F086DEC591FFFED1677A0F10038AB3E4E
Reporter abuse_ch
Tags:geo GuLoader KOR zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail-smail-vm82.hanmail.net
Sending IP: 211.231.106.157
From: 동하금속 <d55002@daum.net>
Subject: 견적요청
Attachment: 2020 06 08.zip (contains "TRICEP.exe")

GuLoader payload URL:
https://onedrive.live.com/download?cid=78BFB08E0F7BC86F&resid=78BFB08E0F7BC86F%21111&authkey=AGGNhgqj6UhXm2w

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-06-08 09:22:09 UTC
AV detection:
27 of 48 (56.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip f81388c85ae6ec47719aeb51c65974a83a27cc7383b3569ce6a75d8cae6d4b92

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments