MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f4c8829df357db3002865e2afdceef666037b4b55add9b3f3f9bdf604887761. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5f4c8829df357db3002865e2afdceef666037b4b55add9b3f3f9bdf604887761
SHA3-384 hash: a2e70f6ee674fe1666024accc343376a1044eec9bdd488f78cecbf30fc3ff4b0c7cdc367fa337185f0949b23be6e9a11
SHA1 hash: 63274f94692a156d5fc3b4bfed47feec51c9faa2
MD5 hash: b486538cc2da39ade819b64b680a8c7d
humanhash: music-shade-sink-tennessee
File name:Private@customer.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-04-28 04:54:43 UTC
Last seen:2020-04-28 05:59:59 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 00592694c197ff9937aa5f47770761a3 (1 x GuLoader)
ssdeep 384:mWNRYzdRkpi4/CI1j6jxkQHsElcmt3Gy29l3duE7F9+ATaudbOttHgczTkUe50+v:mWN6RLDJywGV3duc9NTauROtSSDeVk
Threatray 230 similar samples on MalwareBazaar
TLSH 14733927F4949265D05847B66A27EBEC035A7F610D08CE933C483F2E5D74E25EB60EA2
Reporter JoulK
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
94
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 5f4c8829df357db3002865e2afdceef666037b4b55add9b3f3f9bdf604887761

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments