MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9518df13e375c4e3926979ddda32a1a11b94eb928364f9b45f35970ac82ee6e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 9518df13e375c4e3926979ddda32a1a11b94eb928364f9b45f35970ac82ee6e2
SHA3-384 hash: 314df7a1f3c519d8e503abdf46535674f9de1798304241d017d45943bfd379c1da5acf3c7ce9d4d6f7a66d27d1112dc9
SHA1 hash: 7fb4d867634326ceac236efdc53a254950ff7890
MD5 hash: 1fee8d135b538567e24faa39b34f0f29
humanhash: virginia-quiet-helium-beryllium
File name:List of required items pdf.vbs
Download: download sample
Signature GuLoader
File size:3'021 bytes
First seen:2024-12-09 12:46:17 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 48:cP49pYOeQgOFQgOH9hfU950t9WDyXaqauF9ZZiq+yXRLcubEF9ZZiQ5Q1PgjE:LxKLJZLvgZPGKE
TLSH T1505177BF0F45C6CE4ACB5808503475E6DFC00A774B3E65AD6E2378E25D7A06A7496CC8
Magika vba
Reporter JAMESWT_WT
Tags:185-236-228-92 GuLoader vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
117
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
obfuscate shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
powershell
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
AI detected suspicious sample
Found suspicious powershell code related to unpacking or dynamic code loading
Malicious sample detected (through community Yara rule)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Invoke-WebRequest Execution
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
VBScript performs obfuscated calls to suspicious functions
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
Yara detected GuLoader
Yara detected Powershell download and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1571488 Sample: List of required items pdf.vbs Startdate: 09/12/2024 Architecture: WINDOWS Score: 100 49 www.puneet.ae 2->49 51 www.astenterprises.com.pk 2->51 53 8 other IPs or domains 2->53 69 Malicious sample detected (through community Yara rule) 2->69 71 Yara detected GuLoader 2->71 73 Yara detected Powershell download and execute 2->73 75 7 other signatures 2->75 10 wscript.exe 1 2->10         started        13 powershell.exe 15 2->13         started        15 svchost.exe 1 1 2->15         started        signatures3 process4 dnsIp5 83 VBScript performs obfuscated calls to suspicious functions 10->83 85 Suspicious powershell command line found 10->85 87 Wscript starts Powershell (via cmd or directly) 10->87 91 2 other signatures 10->91 18 powershell.exe 19 19 10->18         started        89 Found suspicious powershell code related to unpacking or dynamic code loading 13->89 23 conhost.exe 13->23         started        65 127.0.0.1 unknown unknown 15->65 signatures6 process7 dnsIp8 55 astenterprises.com.pk 107.161.23.150, 443, 49705 RAMNODEUS United States 18->55 57 fornid.com 93.95.216.175, 443, 49710 SERVERPLAN-ASIT Italy 18->57 45 C:\Users\Public\tk4f2qxkb.vbs, ASCII 18->45 dropped 47 C:\Users\Public\bsxhli2ob.xlsx, Microsoft 18->47 dropped 77 Found suspicious powershell code related to unpacking or dynamic code loading 18->77 25 wscript.exe 1 18->25         started        28 EXCEL.EXE 73 70 18->28         started        31 conhost.exe 18->31         started        file9 signatures10 process11 dnsIp12 79 Suspicious powershell command line found 25->79 81 Wscript starts Powershell (via cmd or directly) 25->81 33 WMIC.exe 1 25->33         started        36 powershell.exe 18 25->36         started        61 s-part-0035.t-0009.t-msedge.net 13.107.246.63, 443, 49725, 49726 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 28->61 63 s-0005.s-dc-msedge.net 52.113.195.132, 443, 49716 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 28->63 39 splwow64.exe 28->39         started        signatures13 process14 dnsIp15 67 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 33->67 41 conhost.exe 33->41         started        59 puneet.ae 209.124.66.28, 443, 49707 A2HOSTINGUS United States 36->59 43 conhost.exe 36->43         started        signatures16 process17
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks computer location settings
Blocklisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments