MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 b0968bdb6a175a38ec05efcf605ed61411d16e63e692bc0d7b8f1f747ce3b2e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GCleaner
Vendor detections: 17
| SHA256 hash: | b0968bdb6a175a38ec05efcf605ed61411d16e63e692bc0d7b8f1f747ce3b2e5 |
|---|---|
| SHA3-384 hash: | 3805f1b2b078a983527686b920ca426fbae2b90ef58fcb54b0fbc69da43c924ab060972435db23e8376a49734b0774d7 |
| SHA1 hash: | b492d614f7749220b934127cdfc737426797890c |
| MD5 hash: | 8b7d2590f1fb0dfd81b796f4b4723542 |
| humanhash: | jersey-double-arizona-grey |
| File name: | stage-0.bin |
| Download: | download sample |
| Signature | GCleaner |
| File size: | 343'552 bytes |
| First seen: | 2024-11-07 15:55:27 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | b585adb193cc73047fae4142a994b352 (2 x Stealc, 2 x GCleaner, 2 x Smoke Loader) |
| ssdeep | 3072:M4WBLuupGWmJT8kk4nhCvjzgQdeTDKnBmnMPbdyqJD2/OX3kaVw5OvRQ46+a:F4LgWC9k8Cvjz8TDKnBPb0wKWfvRQ4V |
| Threatray | 48 similar samples on MalwareBazaar |
| TLSH | T1EA745C03B2E1BD51E9278B729E2FC6F8366EF5608E59776E2218EE1F14B01B1C163711 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10522/11/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| File icon (PE): | |
| dhash icon | 00044a43468a82d2 (1 x GCleaner) |
| Reporter | |
| Tags: | exe gcleaner packer |
Intelligence
File Origin
FRVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
5.42.65.115
Unpacked files
7c610d2fd42fde5780d57768926e3a5f8575e6905b8a5ea62dd43ebda36759f5
d0d93869aac6091af6c953475915831f4b300377931bb4dac2adcdceeb5616b2
99d42ee02b2d43170796ccb36e5f05318a713fbbb2b48067024a555a58a57dc9
1f4db635b14e316532f5c29e3c03a52459ce43df9517adf81c7b2057450ab037
151ef2d3caa9606e6aa1531750361b3e413433c1f884f4d700304f1c6501978a
4b6032c2677c1c6757eb39e3899812dfe63426af9b094094786c9a0ee4aa31d6
3ffdada986edc6412a966b49b35d63b38d836252f77c4c6488b3b564653f3af7
b85e0613ef25472f1001e21c2cc4c80ccb133477751927cd9d885a6e2d5661f1
029d1969a657a18577dab2bcc61a8c2aabce1d01fdcd9db4b0273e970ed173a1
b0968bdb6a175a38ec05efcf605ed61411d16e63e692bc0d7b8f1f747ce3b2e5
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | pe_detect_tls_callbacks |
|---|
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
| CHECK_PIE | Missing Position-Independent Executable (PIE) Protection | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CloseHandle |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::FindNextVolumeMountPointA KERNEL32.dll::LoadLibraryW KERNEL32.dll::LoadLibraryA KERNEL32.dll::GetVolumeInformationW KERNEL32.dll::GetStartupInfoW KERNEL32.dll::GetStartupInfoA |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::AddConsoleAliasW KERNEL32.dll::WriteConsoleW KERNEL32.dll::WriteConsoleA KERNEL32.dll::SetStdHandle KERNEL32.dll::AssignProcessToJobObject KERNEL32.dll::GetConsoleTitleW KERNEL32.dll::GetConsoleCP KERNEL32.dll::GetConsoleMode KERNEL32.dll::GetConsoleOutputCP |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CreateFileA KERNEL32.dll::DeleteFileA KERNEL32.dll::MoveFileA KERNEL32.dll::RemoveDirectoryW |
| WIN_HTTP_API | Uses HTTP services | WINHTTP.dll::WinHttpSetOption |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.