MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 242048a88fe7eb08cbd3de9cd13d0dad6f532bd8f85fdd8dcee59d7289f6c9ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 242048a88fe7eb08cbd3de9cd13d0dad6f532bd8f85fdd8dcee59d7289f6c9ab
SHA3-384 hash: 02e97466b1b9759e3ebeb8fa4f5693c6c69d3e061d0d57fa753f9b759e58dbbfefa34be9b72182094a44a5d9302a2be8
SHA1 hash: 1607a4323eafb42ce24dded786912cefe76f8c76
MD5 hash: 7fa224b6603c5f25f708ffe77c6f6611
humanhash: kansas-black-east-tango
File name:SecuriteInfo.com.Artemis7FA224B6603C.9760
Download: download sample
Signature GuLoader
File size:188'416 bytes
First seen:2020-04-24 09:43:46 UTC
Last seen:2020-04-24 10:36:45 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 5761b47cbf756cfae4ecb15e5316463c (1 x GuLoader)
ssdeep 1536:weCS0GxI/zEdRcxONp82N3bAw/85qAm8YXjKN2KxKbRJIx4FBHlvt:wpS0Gq7O+2G2F1E5UeN2fvFF
Threatray 835 similar samples on MalwareBazaar
TLSH 9004E6607D3894B1C63407703DEBD26AD3607ED6D9E54A4F3101B76EEE321862AF606E
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 242048a88fe7eb08cbd3de9cd13d0dad6f532bd8f85fdd8dcee59d7289f6c9ab

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments