MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 095a2bb6539c034a60a7a07f4d507764adde59588e22952b387af48801f042f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GCleaner
Vendor detections: 10
| SHA256 hash: | 095a2bb6539c034a60a7a07f4d507764adde59588e22952b387af48801f042f0 |
|---|---|
| SHA3-384 hash: | 5dbe1d475dcbb564dde341189172e723173f0ea603de274a4568e490b0ac7e75e84016de12adfa1c8206992dedd5c3c9 |
| SHA1 hash: | fa41cacc5cb2762f7f4ebdc099732955efe6d603 |
| MD5 hash: | 31fa32c15a4c25da7ad9234cac460045 |
| humanhash: | fix-black-hydrogen-louisiana |
| File name: | file |
| Download: | download sample |
| Signature | GCleaner |
| File size: | 258'048 bytes |
| First seen: | 2023-10-05 23:06:01 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f7870f247b6310288a9657f261d28969 (3 x GCleaner, 1 x Tofsee, 1 x Smoke Loader) |
| ssdeep | 6144:Rb49KN6SjSAEMRVW/nAOclm6KkzwTrpt:Z49d8V+An/k |
| Threatray | 86 similar samples on MalwareBazaar |
| TLSH | T14E44F12276D0C8B2C85B8D398425CB64AB37647166AA468BF39417FF5E303D2973B34D |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10523/12/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 080808680e070600 (1 x GCleaner) |
| Reporter | |
| Tags: | exe gcleaner |
Intelligence
File Origin
USVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Unpacked files
12cd64a6d63eb4c7ae10c011a65ea69f9ce0022197d39cb454cc63fc7e147f78
658d9ea4093e492a0f1a8cc6e054e65d2ea30f22fd179b1e1ca58c17618690e9
a4f2367e3e2e9a8ce919fde4522d4a347e30fa7625ff391b082a5c830acb1a76
030c0eab77f63f34b1d09730a8d01a6e5c128c564f75e8f24dddf1a9c1917507
53d10bf98c4e290949b6efe10418a674c737c837ad85fcd47baeeaaa8d72ddcf
92f8faa5180fb698b2313532039b120227e32255dfacf2b3139a4b3734a1fe0c
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.