MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4adf106d80dd2be5d8ea333dcc3a1d06770e4d913b25d05616247f9c66f99484. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 4adf106d80dd2be5d8ea333dcc3a1d06770e4d913b25d05616247f9c66f99484
SHA3-384 hash: a650298a04da7e7a28d55930904ee2fd125eab0d028fa709fc100a0aa09966c7c1ccb1b57b42727556bad68588b6c7ef
SHA1 hash: 63cf112b40910dd658088a24cd114e9eae6add1c
MD5 hash: c81e9f40522058d98cdc6c9753022499
humanhash: lithium-speaker-eleven-hot
File name:SecuriteInfo.com.Trojan.DownLoader33.35980.28619.9113
Download: download sample
Signature GuLoader
File size:217'088 bytes
First seen:2020-04-24 11:39:26 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 63fb6e528f422fd79ec15229e6c5a714 (1 x GuLoader)
ssdeep 1536:8FIkBFQBh+K2z6KU1rIq8zFzy728YqVPYjYVxJff0sou/c3W0IffQDwkn:8FPuBg9oURzA7FY8NRc7eQiQV
Threatray 283 similar samples on MalwareBazaar
TLSH ED240841BD789863C71486306EE6EBBEC2483DD4E9E1C94F2080B75AEF33796159216F
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 4adf106d80dd2be5d8ea333dcc3a1d06770e4d913b25d05616247f9c66f99484

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments