MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe9c4713a117b88c7b1c7adefcafe164cab311dcf6d7a1ae7a9569c9bb65b705. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: fe9c4713a117b88c7b1c7adefcafe164cab311dcf6d7a1ae7a9569c9bb65b705
SHA3-384 hash: 749b3f179f9a859234b8e957540d0e9ded87df41660c79868cc223c037025b9e43246438e41656cc483600f12ad5c5b0
SHA1 hash: d3ad04af825fda3bb183bea77696f887042cf692
MD5 hash: 99543e606c46dce805e8c356522c479b
humanhash: purple-beryllium-nevada-cat
File name:PO-COVID 19.bat
Download: download sample
Signature GuLoader
File size:102'400 bytes
First seen:2020-03-31 07:16:44 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash af2e76a55362ad1cbd4349b26c659528 (1 x GuLoader)
ssdeep 1536:TzDQj1sDxEHTYNVgo0o1bcaeMFWTkMakbB4:DKiyTwz0m7V
Threatray 718 similar samples on MalwareBazaar
TLSH B7A3E702FE00BDA9D1284DB68B728ADD13467E256E45AE03348C3EDE7AF01943152FDB
Reporter abuse_ch
Tags:COVID-19 exe GuLoader


Avatar
abuse_ch
COVID-19 malspam distributing GuLoader->404Keylogger:

HELO: r2.s150.mail1.smtp.beget.ru
Sending IP: 185.78.30.105
From: info@lubcom.ru
Subject: Purchase Order (PO For-COVID-19 Products)
Attachment: PO-COVID 19.zip (contains "PO-COVID 19.bat")

GuLoader payload URL (404Keylogger):
https://drive.google.com/uc?export=download&id=1fILMgZc6MBNGQVrpA3SaVzzEPZ0NFsML

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-03-30 15:50:59 UTC
AV detection:
26 of 30 (86.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Dropping
404Keylogger
  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments