MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14885a4bfd76cdb49db108d03ce3a8c88c301c786eed577606aaacc49d673bfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 14885a4bfd76cdb49db108d03ce3a8c88c301c786eed577606aaacc49d673bfa
SHA3-384 hash: 03541539bd33dab9b3e8f0246be178e644e3b2252d50655f019c0f4a9267430bcbd9461466fa53244bce8bd0c74ee2e9
SHA1 hash: 3d723a58e2081da30a843d1474b9209b59af3318
MD5 hash: 0b0fe2a429e0a06cc7b7d70d725badc3
humanhash: magazine-football-lion-zulu
File name:QUOTATION.exe
Download: download sample
Signature GuLoader
File size:98'304 bytes
First seen:2020-04-06 05:28:18 UTC
Last seen:2020-04-06 06:39:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d618b197660bdd9d6e936cae08c91e6e (1 x GuLoader)
ssdeep 1536:SSc9Bx2cHQCmh36WTmCX3j/w7kJmv0QMoGF:i8cjK/Tp3j/w7kJmvZMom
Threatray 1'356 similar samples on MalwareBazaar
TLSH 80A3B411FAA8FE51C4149EB1893ADAEC4535FC35DD01AA47BAC83F6E3C30191B652B1B
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
80
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Agensla
Status:
Malicious
First seen:
2020-04-05 10:48:28 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaFileOpen
MSVBVM60.DLL::__vbaErrorOverflow

Comments