MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82089a8061b74b167c57018108ddf90cc8f7da8b6eeecdeaa05467d8f201b255. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 82089a8061b74b167c57018108ddf90cc8f7da8b6eeecdeaa05467d8f201b255
SHA3-384 hash: f6493a5ca0553034385e2702d6e3d2453a746239c31c1231c4d183dd3cbe7c9aeb893e34aa402608a71120244517e745
SHA1 hash: c82eadc8341e8bf69be2bcc6569384e3598d3fd7
MD5 hash: f14ecc3de13d1d328c95cc92074fe17a
humanhash: bulldog-minnesota-sixteen-hotel
File name:Shipping Invoice No. 024.exe
Download: download sample
Signature GuLoader
File size:106'496 bytes
First seen:2020-04-14 14:09:00 UTC
Last seen:2020-04-14 19:03:06 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f515caa0b268750b905d768646d3df0a (2 x GuLoader)
ssdeep 768:ag28/EpJ33JLSzr6U5ejun6FTQ0oyZgf1NiBFF+gCtwS2SEOKWl0O:DlMpFurX4EDyGdNQ+NtL2SH5
Threatray 936 similar samples on MalwareBazaar
TLSH 06A3D521B6A0FE51DA120E714DB6CEEC8521FC34DD80664771CA3E5F39B16A4BA32B52
Reporter jarumlus
Tags:AgentTesla GuLoader

Intelligence


File Origin
# of uploads :
3
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments