MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66a2bf82afdb19daffd125afa2f94c6801fefd75b7759c10e2c0f8aec62fb795. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 66a2bf82afdb19daffd125afa2f94c6801fefd75b7759c10e2c0f8aec62fb795
SHA3-384 hash: c14ab7d638467ef3337a1a44093bd6e895837dfb4b60116e116c18aa38cda91e079f4c6b6161f66ff56c7148d6c687d6
SHA1 hash: 423b2514b2dc1a2847f5f819cdaaf5b2b0946c7b
MD5 hash: 9d7a135637ca118231e8dffccbb7cfde
humanhash: foxtrot-tennessee-echo-salami
File name:Amended PO.exe
Download: download sample
Signature GuLoader
File size:81'920 bytes
First seen:2020-04-28 05:07:01 UTC
Last seen:2020-04-28 05:59:49 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 9e73c54c6bb022fd205be993b54b5f98 (1 x GuLoader)
ssdeep 768:xX7jZn6w/2A7CuEudC61btvClGXClRruD6EspoQD/s8:xLht/2K8us61xSuoKspoj8
Threatray 421 similar samples on MalwareBazaar
TLSH 0A832B19B998E572C54885F91F27C7BC52677C30CE84DD073988BFBD2935A91BAA030B
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-27 19:40:00 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
24 of 30 (80.00%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaLateMemCallLd

Comments