MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d7421e6d0ac81e2292bcff52f7432639c4f434519db9cf2985b46a0069b2be8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d7421e6d0ac81e2292bcff52f7432639c4f434519db9cf2985b46a0069b2be8
SHA3-384 hash: b6b14195b430d21bd18dfb14b41acea79b173ef668047fb7342201685ab793b524983f980a47ee46148e88df8fe3fa07
SHA1 hash: c61b31c7dbebdd57a216a03a3dc490a3ea9f5abd
MD5 hash: d2e2c65fc9098a1c6a4c00f9036aa095
humanhash: triple-delta-lima-lithium
File name:d2e2c65fc9098a1c6a4c00f9036aa095.exe
Download: download sample
Signature GuLoader
File size:65'536 bytes
First seen:2020-05-30 09:26:09 UTC
Last seen:2020-05-30 10:53:40 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 6a38de66ed1038b4600aca30e494f049 (1 x GuLoader)
ssdeep 768:IPqTXu0Ee0J9PL8Ln0Rq4YK7NqqhGiZRYPPCI/YzHC2munTDWXQeYJurR:9T+0wH8Lnej597Yhw5TDWXQ3u
Threatray 816 similar samples on MalwareBazaar
TLSH 7F533E2B7E459112E1421A302C64D556BF36BC335806AE1BB6C4AF2DE83148BF9F132F
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1ELoiNSVTziaBatbVNZQWxal_RsriCCrt
http://ffacscs.ug/nw_kUILGeMGK73.bin
http://blockchains.pk/nw_kUILGeMGK73.bin

Intelligence


File Origin
# of uploads :
2
# of downloads :
77
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-29 19:06:08 UTC
AV detection:
21 of 31 (67.74%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
persistence
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Adds Run key to start application
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 4d7421e6d0ac81e2292bcff52f7432639c4f434519db9cf2985b46a0069b2be8

(this sample)

  
Delivery method
Distributed via web download

Comments