MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4308487d53d3dc60b85e3aa3ed9753591d34c0ddba9ab1da7e0e9f6117535144. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4308487d53d3dc60b85e3aa3ed9753591d34c0ddba9ab1da7e0e9f6117535144
SHA3-384 hash: 335ad8277fd87224543f9dc36ce06693dd80366537e944662e068c796775f395b973b03eda224487c1d2e3031ab11844
SHA1 hash: 24bf56804258b9a1da8086162bb809e241f95e58
MD5 hash: 122c24b0f008d2f18939deeded7f4705
humanhash: fanta-avocado-magazine-three
File name:pg.exe
Download: download sample
Signature GuLoader
File size:110'592 bytes
First seen:2020-05-25 14:47:29 UTC
Last seen:2020-05-25 16:11:53 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 9b611398fee943f9147433bbd7199133 (1 x GuLoader)
ssdeep 1536:a1lBKLmVO7rk7WoG9XBdKdD/d4A1SsztXLQiyTVC:a1loLpXisXsd4aztvR
Threatray 169 similar samples on MalwareBazaar
TLSH A7B3E712F6C8ACE5EC214EB118DA9FA85D2AFC611C116B07351AB72E25B7D851FF430B
Reporter James_inthe_box
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-25 14:47:22 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments