MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 308336495b7fa2af7107a520ec1fdcaac4a0d615e0ecfd8ddd6090c72c3f46b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 308336495b7fa2af7107a520ec1fdcaac4a0d615e0ecfd8ddd6090c72c3f46b6
SHA3-384 hash: da63800c99f9b950ff38d1c39b0ac903eb0e3abe7542709fd849780b280e5d5228330d7d1d4108b2e39a402abeadcfef
SHA1 hash: 3341a0e5d2e207ae2f5f62469c6ce26bdb881761
MD5 hash: a907777c840e539bd0a53d402fb16f17
humanhash: uncle-lamp-tennessee-arkansas
File name:Payment Advice Ref SCB100736792577.bat
Download: download sample
Signature GuLoader
File size:110'592 bytes
First seen:2020-05-24 19:45:41 UTC
Last seen:2020-05-24 20:36:18 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 7766f829ac6161b37f030305799c07cb (1 x GuLoader)
ssdeep 1536:XV5Gv9JF78LhvQguBL8KHCcdKhT7WwJjjS:FYv9L8Vv6LlHCcdKhE
Threatray 5'248 similar samples on MalwareBazaar
TLSH C1B3C313B6E8EC96EC016EF14BE1ADA44D63AC305D508F43B54BBB8D36375E91FA0609
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
3
# of downloads :
78
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Beebone
Status:
Malicious
First seen:
2020-05-24 20:35:24 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
26 of 31 (83.87%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 308336495b7fa2af7107a520ec1fdcaac4a0d615e0ecfd8ddd6090c72c3f46b6

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments