MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1794a70ea1648e95eb6c74976b5d9e88e1464328b339da71e3cd864e20838d5e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1794a70ea1648e95eb6c74976b5d9e88e1464328b339da71e3cd864e20838d5e
SHA3-384 hash: d9c74f99e9ee96359dd91ff00abf8df1976027a43e757cd4dbcfd35c72ac55e515ed6bbd2835ffe594e8206a8ead7450
SHA1 hash: 0ad3545502e6ea8327057e8c1a212091bd1148fc
MD5 hash: bc960af52788661ce34193975df63f82
humanhash: white-fillet-victor-music
File name:INVOICE.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-04-30 08:20:39 UTC
Last seen:2020-04-30 09:44:51 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f22ed3a63bc3015953114e2a22c69299 (1 x GuLoader)
ssdeep 768:Y2c534Nadoi0mpLYE5sreUV4LjIRyJP5CK+Fzku:q534goi0mFzy6G8ayh8z1
Threatray 118 similar samples on MalwareBazaar
TLSH 6E733B5BF2A8D937EF654AF26B23DBA849677C708D889C033D547B2CD631B48EC50246
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaLateMemCallLd

Comments