MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 845e969b751df1e263bcf033a16c1f49ece421d2ae8133bd04714bc0df71b088. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 845e969b751df1e263bcf033a16c1f49ece421d2ae8133bd04714bc0df71b088
SHA3-384 hash: f3e50a0acef658d4ae7c0dc5038174fecc6f49bce51838f0f3f08e2e1634ae7a8bb1b3d70bc8d5132d0850d38982b9c3
SHA1 hash: b84b3f034c6b5f92544d819f6034454091215a53
MD5 hash: 29093818829a2569d7aa60bbe6429f61
humanhash: paris-may-harry-item
File name:Pb@fb2Quote.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-04-28 04:51:11 UTC
Last seen:2020-04-28 05:59:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash c849c63611a27089ec7dfe0fe72ffe04 (1 x GuLoader)
ssdeep 768:QL7+5GltNd4sdux51Wept1serQqsQVwMdlNw5:w8ydUxTWO1hsQVwMdq
Threatray 291 similar samples on MalwareBazaar
TLSH 50733C16B6D09872D1794EF41E75CAF90286BCB50D98CD47B0943B2E2D38F4ADCC1AA7
Reporter JoulK
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
92
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 845e969b751df1e263bcf033a16c1f49ece421d2ae8133bd04714bc0df71b088

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments