MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1f93e9ec506b2df6670b01905f5c42e05d7c2b4dbf44e37d82ee8050528d961d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1f93e9ec506b2df6670b01905f5c42e05d7c2b4dbf44e37d82ee8050528d961d
SHA3-384 hash: f24af47d6e9123aca87252a8bae2fca2f9224f9fc96cc2d6bf24e7934c67111a30a9b0748d904a0ab8c88c6efc6e41c0
SHA1 hash: 65561049a2b5f3ea21246c19d69a6c0e21b93eb3
MD5 hash: 189627fd5fda14d3f1d9471c072cc0a7
humanhash: jersey-helium-carpet-uranus
File name:PAYMENT ADVISE.exe
Download: download sample
Signature GuLoader
File size:221'184 bytes
First seen:2020-04-21 20:08:47 UTC
Last seen:2020-04-22 08:47:06 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash a8038af48df4b2c8388fa556e1deedcc (1 x GuLoader)
ssdeep 1536:4KPixrcP9LawvviYW81X3Nci8Y8HK+4Z5urALApFN+cg+hzgI6uaOJxjMbx3/Fj4:P+ajl1HKnXH6d0x+c96ulibJ51Ji1/
Threatray 391 similar samples on MalwareBazaar
TLSH 7D24F685AEB8A923C71846306EE6D7F9C20C7DD0E6E5C94F20443B1BAF3374615A652F
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
5
# of downloads :
87
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments