MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 67283e72feeed3ec5c8b7314fd13fe8936a1bf2bc8bde5fb54048c630a57598d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 67283e72feeed3ec5c8b7314fd13fe8936a1bf2bc8bde5fb54048c630a57598d
SHA3-384 hash: 6e3c31cecad53adcdf5bfc222521856f820178fecbb119f045a7b0fcfa4de840a17dd11b0779bfe45bc1399c2e5a1c36
SHA1 hash: 5b0dd4bc1f3d5be88f074d29a842ccbdb379239b
MD5 hash: 46f7f2bf5bcc1fd867bd6b86657d6840
humanhash: connecticut-cold-item-early
File name:SecuriteInfo.com.Mal.FareitVB-AA.18911.23604
Download: download sample
Signature GuLoader
File size:188'416 bytes
First seen:2020-04-24 11:39:27 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash d35b6d8b16130e587fe1890b9666dc8c (1 x GuLoader)
ssdeep 1536:mWmViqTQtCBsRgxGkq8wvzsQm827nkpVggEpkYszwDKVPCd0ekVN0:mWSzQtYDRwYq2gEiYsu4f0
Threatray 596 similar samples on MalwareBazaar
TLSH D20407A13D3891B1E52007382EEAC6BAC351BDD5D5E4464F2041B71EFE722D729F622E
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 67283e72feeed3ec5c8b7314fd13fe8936a1bf2bc8bde5fb54048c630a57598d

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments