MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92d33ffba60dd98d6e60e4487618f808da7bb78ba1a69904edb440a4ecbae4f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 92d33ffba60dd98d6e60e4487618f808da7bb78ba1a69904edb440a4ecbae4f6
SHA3-384 hash: 96da2497c2cff594cb4f3fa22327209dbe9efe629e1a4af8e3dbf2c57a2962b4da077225603735b2b21136e7629456c8
SHA1 hash: 36c839caf96c18ab8b16bf1fb41b9ca633059721
MD5 hash: aeedcc9793ba32114bcf770af7618c01
humanhash: lion-eighteen-april-wolfram
File name:SecuriteInfo.com.Fareit-FTAAEEDCC9793BA.11148
Download: download sample
Signature GuLoader
File size:114'688 bytes
First seen:2020-05-11 19:04:34 UTC
Last seen:2020-05-11 19:49:51 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 74b2919677e7172a9e5047d432d6f0f1 (1 x GuLoader)
ssdeep 1536:3a73MSjcpx/JW0FijxOMr2rS78xSBAgljPOwcAdDSZOvE/wizsv0POW:3o8rvRMvETAv0R
Threatray 84 similar samples on MalwareBazaar
TLSH EAB3F70456E8E11BDABF8DF25B9172C9D2AEAD3E7405761317C1330EE73A481E68137A
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-11 19:35:23 UTC
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe 92d33ffba60dd98d6e60e4487618f808da7bb78ba1a69904edb440a4ecbae4f6

(this sample)

  
Delivery method
Distributed via web download

Comments