MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 71ba6b649b4ea43c7139f5d429d2ec449f129fdc588c103546d5970a6db33103. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 71ba6b649b4ea43c7139f5d429d2ec449f129fdc588c103546d5970a6db33103
SHA3-384 hash: 19a538c55f761cf6270026b7c04f256ccb4fec8ad23bb6c5c8550018d2add38f9f32e2235f429a0d5998820067158f98
SHA1 hash: 29d6e0c7ba5ca8200bf527c7797dbd0a07d95d0d
MD5 hash: d5e4c04f8373b69e9449c5120c8c8816
humanhash: michigan-edward-enemy-twelve
File name:SecuriteInfo.com.Win32.Injector.EMFR.913
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-06-02 08:34:01 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash c0eed97d953c2e27abd3ddb804fc2cb1 (1 x GuLoader)
ssdeep 1536:54FO8lLSqgzr+o1BITxVDlWLzwKQwpDHcPqzWpA:zzrpcXDlIzwPt6
Threatray 1'378 similar samples on MalwareBazaar
TLSH 0B9319437AD48501F1B24A712E7B82996F25FC2A5D839A4F344D2E4B7B317629C6C32F
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-06-02 06:31:48 UTC
AV detection:
17 of 31 (54.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
persistence
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Adds Run key to start application
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 71ba6b649b4ea43c7139f5d429d2ec449f129fdc588c103546d5970a6db33103

(this sample)

  
Delivery method
Distributed via web download

Comments