MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 17e0971dd39c6cede948706786eb03cdd7077028dcf94ae3d16a03356256a1d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 17e0971dd39c6cede948706786eb03cdd7077028dcf94ae3d16a03356256a1d3
SHA3-384 hash: b0ca87f0bc2a4c1f87a0fb5cd385663d61cdeffc3c5dabe7237a09cbd95d42bd11123d4e38a73d668099a8bddc6b58d8
SHA1 hash: 4beedacf266c541f2856c460dee9a69033c20a41
MD5 hash: b55f88041fbc0e2a51d562d18a1764d9
humanhash: princess-beryllium-alpha-snake
File name:our.jpeg
Download: download sample
Signature GuLoader
File size:98'304 bytes
First seen:2020-05-21 05:53:32 UTC
Last seen:2020-05-21 05:56:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash a8d8fe0abea1fbb9a352d6654ad1f4d2 (2 x GuLoader)
ssdeep 768:/cwPW/xFwui2ZRMcaIh1yRu0B1f4kQfKOD05KZtqA9YAaFOXvV9R5DzjR:juG2Eckv5QfKO08i1Fg
Threatray 31 similar samples on MalwareBazaar
TLSH 45A3F962F9A8EDB1D62846FD1E709B681967BC344D12CA0B70C5773C1DF364A683172B
Reporter cocaman
Tags:GuLoader jpeg

Intelligence


File Origin
# of uploads :
2
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-21 06:27:05 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
19 of 31 (61.29%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments