MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3df521e9d317f61aa62f5156f18ef03ecee2dad470665ba4932719275af87071. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 3df521e9d317f61aa62f5156f18ef03ecee2dad470665ba4932719275af87071
SHA3-384 hash: 645ac8ae1c1250dfe7f5f5b50439ce8ca80d129a0dc41a55f6a20a7969222dfb6d14a7da38233656901a588ff22d3bf5
SHA1 hash: 98346a31eac37ee0782cfc3867a49a86e6968826
MD5 hash: ee5237ced437943e28804114a89fd5ab
humanhash: cola-enemy-snake-cold
File name:A21667235.xlsx
Download: download sample
Signature GuLoader
File size:138'634 bytes
First seen:2020-06-05 13:40:38 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
ssdeep 3072:i1D7Mf83NqC5zKXrPsiNUBDSlQOfOuxb7juKazUc5:sD7Mf83NX9grPsYcDSl9fsd
TLSH C1D31239C42383A5CEAE71B2C7F0D420DF487467855D58DBA75D90AE63C62AF207F886
Reporter jarumlus

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2020-06-05 11:37:36 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Enumerates system info in registry
Launches Equation Editor
Modifies Internet Explorer settings
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Checks processor information in registry
Blacklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Excel file xlsx 3df521e9d317f61aa62f5156f18ef03ecee2dad470665ba4932719275af87071

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments