MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93379d7c4b130e722ae0e0a1ff1ac06d40fd7343ca1436bdfcc487a28a7a9e8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 93379d7c4b130e722ae0e0a1ff1ac06d40fd7343ca1436bdfcc487a28a7a9e8f
SHA3-384 hash: ad04f795a709a25c5a3bc8e7c093e4c57079c5b1027f128e91683f28be55e4283b51f8ce400289d0201c1a144e375de6
SHA1 hash: 49cd94d93cd7ff49927544608212f7614dca8e3c
MD5 hash: e581997848ff6f16f2afb5dc4a07005d
humanhash: idaho-seventeen-table-yankee
File name:Scan Copy New Q201.doc.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-04-27 19:05:08 UTC
Last seen:2020-04-27 19:45:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash cd6f1128c24c42c9fc6a8275de1b632b (1 x GuLoader)
ssdeep 768:PNFh5jtwCRHyRgmJhAAqV3PtaYlJruHwpbkpWgEbIZTfqMF/LU:FFXvIg/VFaGmpWgEbIZ+MO
Threatray 770 similar samples on MalwareBazaar
TLSH D7731A19F5B0D5B2D22DA6F11E5286E87952BC30C908CD2375CC3B2E2E74D9BA6A0747
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
91
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Malrep
Status:
Malicious
First seen:
2020-04-27 19:05:40 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaLateMemCallLd

Comments