MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3df521e9d317f61aa62f5156f18ef03ecee2dad470665ba4932719275af87071. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GuLoader
Vendor detections: 2
| SHA256 hash: | 3df521e9d317f61aa62f5156f18ef03ecee2dad470665ba4932719275af87071 |
|---|---|
| SHA3-384 hash: | 645ac8ae1c1250dfe7f5f5b50439ce8ca80d129a0dc41a55f6a20a7969222dfb6d14a7da38233656901a588ff22d3bf5 |
| SHA1 hash: | 98346a31eac37ee0782cfc3867a49a86e6968826 |
| MD5 hash: | ee5237ced437943e28804114a89fd5ab |
| humanhash: | cola-enemy-snake-cold |
| File name: | A21667235.xlsx |
| Download: | download sample |
| Signature | GuLoader |
| File size: | 138'634 bytes |
| First seen: | 2020-06-05 13:40:38 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/vnd.openxmlformats-officedocument.spreadsheetml.sheet |
| ssdeep | 3072:i1D7Mf83NqC5zKXrPsiNUBDSlQOfOuxb7juKazUc5:sD7Mf83NX9grPsYcDSl9fsd |
| TLSH | C1D31239C42383A5CEAE71B2C7F0D420DF487467855D58DBA75D90AE63C62AF207F886 |
| Reporter |
Intelligence
File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2020-06-05 11:37:36 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
5/5
Result
Malware family:
n/a
Score:
8/10
Tags:
n/a
Behaviour
Enumerates system info in registry
Launches Equation Editor
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.