MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 012b683060a510c536e2aff1fabc3b4e7436923235754cb28fd3cc18c916eb4c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 012b683060a510c536e2aff1fabc3b4e7436923235754cb28fd3cc18c916eb4c
SHA3-384 hash: 7175b2a58247f93f0425704988b9b72c2e6cf4c228060466a60888335ad3389f9805d1a07db6cf8de2bd6afab71be408
SHA1 hash: f73b2649bce1a7e7a6e197d127f6ce263bd20c6e
MD5 hash: 9467f8f74ad0101e6307d9011c20505f
humanhash: illinois-river-helium-virginia
File name:INV-116030-Revised_VIHA.bat
Download: download sample
Signature GuLoader
File size:143'360 bytes
First seen:2020-03-26 09:46:47 UTC
Last seen:2020-03-26 11:37:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 0a1351d572b7323beae854c719e3e33f (1 x GuLoader)
ssdeep 1536:t1Mk0zpz1XVIu0+KuqNwx2Gohr0MNn3kE9o:t2kGlIEKuio2hOonM
Threatray 664 similar samples on MalwareBazaar
TLSH 1EE30B33FE14C495DC420A304B9D839A4925BC70A99FAB9733817B9EDCF6B179CA1394
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments