MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 65ec71a21b121cb6b5ad5c16425f217589eac46a8879aad3a8f04f5e5b2d872e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 65ec71a21b121cb6b5ad5c16425f217589eac46a8879aad3a8f04f5e5b2d872e
SHA3-384 hash: 81c99443d41d6d039cb5835f4507667e73bb7e82676867f15c3fdfe15075c196d48039231e9c91a60b02da9be77360d5
SHA1 hash: 8fb76739fdb29c79269ce2c98c7bb15203e1f440
MD5 hash: c909511407214383e2774feb86235a16
humanhash: wolfram-bulldog-finch-music
File name:Tjavsendeudt7.scr
Download: download sample
Signature GuLoader
File size:114'688 bytes
First seen:2020-06-04 04:27:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 5560a6019b700bf09a9cd989d3f752f4 (1 x GuLoader)
ssdeep 1536:wSPfxV40PkXe+Ajf1WkgrKHxLdGKc+o0FDHdZ1gIIYOV5WkVttrb4SKYJ:ZPXPkoj94KVdhjFD9z0VV5Kk
Threatray 1'003 similar samples on MalwareBazaar
TLSH 2EB36C03EE4D8553C1888FFD2D135D7A7B1CA94A0D401BEF627A6DAAED316432C9B21D
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-04 04:35:26 UTC
AV detection:
22 of 31 (70.97%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  5/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 65ec71a21b121cb6b5ad5c16425f217589eac46a8879aad3a8f04f5e5b2d872e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments