MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8def2806af1018108aea2523b671471051aa156f4d837d16369b7f1154c0a5a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 8def2806af1018108aea2523b671471051aa156f4d837d16369b7f1154c0a5a7
SHA3-384 hash: 69d9f5a383aafbef56288fd5391a0fde2dedb2711da82a5fad57fd1217378f2f67adf6f57104bb7f084d3c29024c58db
SHA1 hash: 9919d98c6e724dad3b2d00375d04dd2cdafaece2
MD5 hash: 8150cf9b25d79f9378b6ed712958b575
humanhash: xray-winner-ceiling-golf
File name:d.exe
Download: download sample
Signature GuLoader
File size:110'592 bytes
First seen:2020-05-25 14:47:47 UTC
Last seen:2020-05-25 16:12:05 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f18c8398c09e8284b5a82a5315383c8b (2 x GuLoader)
ssdeep 1536:L4vdetkcbpK9fCFL1xjRNMZ/FClYqBrtD4+xvH:LQItS9eL/RNA/FClYqBZ
Threatray 295 similar samples on MalwareBazaar
TLSH 7AB3F64375E5AC92ED0A2FB14FE46DB90D33BD612C505F07F44BBA4E6A370882BA1716
Reporter James_inthe_box
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-05-25 14:47:40 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments