MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1252cf08c8e83b899bd8b618b20950cde162f897cd6462aa64060e29c61c29b4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1252cf08c8e83b899bd8b618b20950cde162f897cd6462aa64060e29c61c29b4
SHA3-384 hash: be9d7b0919a0efdbbbed1214ac3f433d1debb98a148392c6c6462ad17d832d009d7bdde0288cad9d12bb27288a5f95a6
SHA1 hash: 94fea15a043203350254f7a181a49c598d1fc69b
MD5 hash: 592b96688d968197dd7376594d994b10
humanhash: beryllium-snake-mississippi-alanine
File name:AccountStatement_Mandiri.202004011116635.pdf.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-04-30 09:46:13 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e1e391809be1049fc5f1f44665f3afd1 (1 x GuLoader)
ssdeep 768:BGUfhSTJpkomOvCAxJ+cnPbYcaYnNHNYeB54c4ozxiWW8FbV:90xJPnFaYnNtYkF+8P
Threatray 205 similar samples on MalwareBazaar
TLSH 3A93D794AFF8E067E96849F20653815021E96F37EC201A13B2C87E6F7779795C412BF2
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaFileOpen

Comments