MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 691f116a33f2fc98e59cd019c856b9cdb6202de6b09091481b980ef60fecaef8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 691f116a33f2fc98e59cd019c856b9cdb6202de6b09091481b980ef60fecaef8
SHA3-384 hash: 90ce5025fcd8fbb1052ac6bd9ad2a27069dfff29b1c0e869d739a1fd21e88e2cc131bdb65ce2ad00b8ddbabd8f847900
SHA1 hash: 576ccbfd515e99858204a7f380c83a0c292ab1d5
MD5 hash: c67dad6f21ef7e58550c385973fa55bb
humanhash: oscar-harry-one-solar
File name:temp.exe
Download: download sample
Signature GuLoader
File size:192'512 bytes
First seen:2020-05-19 21:40:55 UTC
Last seen:2020-05-19 22:37:06 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0fef289f5288e8aaf26eef5390a58876 (1 x GuLoader)
ssdeep 3072:fAwYFXvTKRoQG1yMq3cO55WwJQU/UHJf1zQJFa/:YwYcigs45bxsHJf1zm
Threatray 698 similar samples on MalwareBazaar
TLSH AC144915E691B42BDEF94EFE5BE29AB5A0D92CBA9500D70379043F2F35F9885E024133
Reporter James_inthe_box
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-19 13:08:24 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments