MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c27feaca7c04d48cd54730df7e4c89dc200d18658fd78c6a3388a94f15dca9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2c27feaca7c04d48cd54730df7e4c89dc200d18658fd78c6a3388a94f15dca9b
SHA3-384 hash: 66901a96cd28d96834b311836607cff3d09f83e46321f3e8938a9639fceb9254544c462eb56b03059eba7f51c5401ddd
SHA1 hash: 691c57f8ce4ce4f44adc91ada5596fd6c8ac5c3f
MD5 hash: f7290ad5910c340169bf125deb68e361
humanhash: eight-october-missouri-leopard
File name:INQUIRY.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-06-02 11:10:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3aede5e5f620c5ae4cb6e1df44337238 (1 x GuLoader)
ssdeep 768:+shc7416N8lBR2zNKux159mUebtaBv9OcD83vvYEpS9jlO7cB9:+sFO8lLzuf5JBFT83YEpS3O+
Threatray 892 similar samples on MalwareBazaar
TLSH E2734B176E0CCA12D6A542B02C57CBAE2F11BC1C46861F9B355EBE67FB323A05C5D22D
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: ascendmolds.com
Sending IP: 79.124.8.199
From: Somchai <sales@ascendmolds.com>
Subject: Inquiry
Attachment: INQUIRY.z (contains "INQUIRY.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1nQOxwwmxJx_dxnk_MUNIb4BIEARRJ6cV

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-06-02 19:08:00 UTC
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 2c27feaca7c04d48cd54730df7e4c89dc200d18658fd78c6a3388a94f15dca9b

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments