MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 faa7cfe559b790d35927b54ea787790c92255564a8dc72cee93c5f117a115a83. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: faa7cfe559b790d35927b54ea787790c92255564a8dc72cee93c5f117a115a83
SHA3-384 hash: 648b44771b1202cad088be1bcd6f9a7eb2b5d4fa63a20f85d0ce345bb3dfc9fa39aa16dbad27d47d96a9a11f3fea1849
SHA1 hash: 89dd9d61dff2bce5833874f5d7b7dc07f10a4c0e
MD5 hash: e5750906543b2dbf98cea412a3cf7f00
humanhash: ten-spaghetti-foxtrot-cold
File name:Quotation.zip
Download: download sample
Signature GuLoader
File size:73'530 bytes
First seen:2020-06-03 13:32:42 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:8o9E4MVo0LCXejCaNc4zHklFBwyRXoXjMWZOcQ1kjbDDneP0QX+eGh:8o9V8o0WujCUFyRXoXAIOcQ+ni03Bh
TLSH 577302AF498FC355A6CB3C6566D4CD06ACFAC3A240672E920CB6C4861C729CBE657F44
Reporter abuse_ch
Tags:GuLoader zip


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mail.panentour.com
Sending IP: 202.129.224.121
From: Rianty <rianty@setiabudi2.panentour.com>
Subject: Request of quotation
Attachment: Quotation.zip (contains "Wadableevasio8.exe")

GuLoader payload URL:
https://mncarteam.com/wp-content/nigga_zkDjEqogR255.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-03 13:38:12 UTC
AV detection:
25 of 48 (52.08%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip faa7cfe559b790d35927b54ea787790c92255564a8dc72cee93c5f117a115a83

(this sample)

  
Dropping
GuLoader
  
Delivery method
Distributed via e-mail attachment

Comments