MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ec3c68f6fa845bcc40ea35365aa204f7e8bdf8010ea20dec2e3ea3f46838e02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0ec3c68f6fa845bcc40ea35365aa204f7e8bdf8010ea20dec2e3ea3f46838e02
SHA3-384 hash: 0768fe4d4bbdd3437ea4268f6a0e8a1b5d47755543ab726f816126becf1fe0db1c55f5978958cf5afd968dc2e8b93476
SHA1 hash: a8bfdaed0eb6962d3fd93ef20577bbc9b7d2d7e2
MD5 hash: 08949dabaf60e4f15a2f6f15f0490baf
humanhash: robert-nevada-pennsylvania-rugby
File name:FedEx Ship Manager - Print Your Labels.exe
Download: download sample
Signature GuLoader
File size:81'920 bytes
First seen:2020-06-01 11:27:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ec23e29c3c72ed92023abd7e45f583b3 (1 x GuLoader)
ssdeep 1536:6hFO8lLzrf2ADT3raZlaXBk0qyV+lfl9B6L33f86x4iiW:I68T3eKuEV+l9GL3f86x4il
Threatray 1'358 similar samples on MalwareBazaar
TLSH B7833917EE0D9A12D1A486712D4787BE2F257C0D48421F8F355EAF6BBB313621C6E21E
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
74
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Malrep
Status:
Malicious
First seen:
2020-06-01 11:39:33 UTC
AV detection:
28 of 48 (58.33%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos persistence rat
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Modifies registry class
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Adds Run key to start application
Modifies WinLogon
Deletes itself
Loads dropped DLL
Executes dropped EXE
Modifies WinLogon for persistence
Remcos
Malware Config
C2 Extraction:
185.140.53.17:9955
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 0ec3c68f6fa845bcc40ea35365aa204f7e8bdf8010ea20dec2e3ea3f46838e02

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments