MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 138c7976b6b5a29a4569f5018d6b925548a9a424fe3a48293f8a1522ba639afc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 138c7976b6b5a29a4569f5018d6b925548a9a424fe3a48293f8a1522ba639afc
SHA3-384 hash: 90bacb0173c2f6b1927b7fa1ef81a959996daaf8665efe7f2673217a3d041593757e8080ce3842857daa249c40dd8196
SHA1 hash: 4df48dc4c2433119a4e83b7a3aacdec393eed757
MD5 hash: 97923e14f5c1f7b249f318accf2ad1e8
humanhash: papa-wolfram-shade-eleven
File name:SecuriteInfo.com.Backdoor.Win32.Androm.C4041802.10122
Download: download sample
Signature GuLoader
File size:86'016 bytes
First seen:2020-05-01 20:36:47 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c0619b31cafb1aa2ab7aeec35eb2cc67 (1 x GuLoader)
ssdeep 1536:iys7QaYiFon9Hi64emlp/I7eXtZjaET0NyT:iN5onVyTpKAZjRP
Threatray 540 similar samples on MalwareBazaar
TLSH 94833A55F2D9E632D61D47F42A3891E810A5FC3059E2CE0F39843B6EAA3AE53D570327
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 138c7976b6b5a29a4569f5018d6b925548a9a424fe3a48293f8a1522ba639afc

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaLateMemCallLd

Comments