MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84f409f8aee0cf253fba68ae4027348449045f7bfb8723ac8fe0336c21c0b0f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 84f409f8aee0cf253fba68ae4027348449045f7bfb8723ac8fe0336c21c0b0f6
SHA3-384 hash: 4e35660fbf5071c168ea60bec4c54822df6708d9c9c9b54185bc10388b10f48d66af6faaea132ca934fd0204e98961f4
SHA1 hash: e12f50d9a16728d85b211325b3774836b5b82cd6
MD5 hash: 0e0e6f0ab817dd91f2952e17662cd5a4
humanhash: charlie-mountain-nevada-nebraska
File name:SecuriteInfo.com.generic.ml.21741
Download: download sample
Signature GuLoader
File size:176'128 bytes
First seen:2020-04-18 13:37:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2d89cd5abeda12bebba4b20f33a3d7e7 (1 x GuLoader)
ssdeep 1536:CN4DFD1SaGCcF4zff8pwI7mlkww0iSubw6OC8YjalyLlH0eo+ByvkAjQ5YVElKzg:ttHcFmfkpnilkhrbcRivbOsKM
Threatray 433 similar samples on MalwareBazaar
TLSH 8E04D656BE70E062D11407B06D6AC3EAD2607DF5D8E5848F2080FB2FEEB15D268D129F
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 84f409f8aee0cf253fba68ae4027348449045f7bfb8723ac8fe0336c21c0b0f6

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments