MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4b632e01957edd0717ec241f31b52bee90b2060d1a99e1467c842f0241d68d02. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 4b632e01957edd0717ec241f31b52bee90b2060d1a99e1467c842f0241d68d02
SHA3-384 hash: a1b2a2024c8385f4ce4b96bf093460687e4d4ca056adda4715b698c5bd7194e4d0a086675379ddad92c10c797d96d127
SHA1 hash: bd07e12179bc5325b6d3ec713ba76ff36313208d
MD5 hash: 894802068528cfd7a5488c7c0ce785d0
humanhash: early-maine-august-sodium
File name:894802068528cfd7a5488c7c0ce785d0.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-06-02 07:44:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash e5b3b4e5a5a8ca119b91dc7b36cb061e (2 x GuLoader)
ssdeep 1536:TIlFO8lLUQk/13RRBv9M8aLzwKQwpRDj3VSdT:dVRRM8szwPYe
Threatray 787 similar samples on MalwareBazaar
TLSH A59318076AD88511F1B24A702E7B82996F25FC194D878A0F350D5E4B7B31766ACAC33F
Reporter abuse_ch
Tags:exe GuLoader Pony


Avatar
abuse_ch
GuLoader payload URL:
http://ratamodu.ga/~zadmin/group/pm_FBUoVd204.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
126
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Vbkrypt
Status:
Malicious
First seen:
2020-06-02 07:35:59 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
18 of 31 (58.06%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 4b632e01957edd0717ec241f31b52bee90b2060d1a99e1467c842f0241d68d02

(this sample)

  
Delivery method
Distributed via web download

Comments