MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b33804d1bcadb3c28baad638d82f7510ab66451a5a602978dfa8f629e6bdca05. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b33804d1bcadb3c28baad638d82f7510ab66451a5a602978dfa8f629e6bdca05
SHA3-384 hash: de486635c6c7e3c0601c4fecbc7998da87febc939f888a91374337976ebfcb39d2fb9809fb90e7aef13e4cd43ea4f88d
SHA1 hash: a6b5dfacc77b57bd12a7ca6a37e69992bd309802
MD5 hash: 455558a703168177855a968577d73afe
humanhash: emma-high-wolfram-eighteen
File name:Xeros_ Scan _ Covid_19_ Urgent_information letter.xls.exe
Download: download sample
Signature GuLoader
File size:110'592 bytes
First seen:2020-04-14 09:31:57 UTC
Last seen:2020-04-14 10:54:54 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ecb3b6519153e25618e7dbab86ae8470 (1 x GuLoader)
ssdeep 768:IbeCKUD5F/PATnJEdV9doBnoA2EP8oGXIqZgfCM5jOLAnXGs:m/j5F/PAnJEH9EioGXhmCcOLIXV
Threatray 135 similar samples on MalwareBazaar
TLSH 94B30722F984FE80C9065AB34EF9DAAC9402BD349C55364734C53F1F367A1E0B656E87
Reporter abuse_ch
Tags:COVID-19 exe GuLoader


Avatar
abuse_ch
COVID-19 themed malspam distributing GuLoader:

HELO: oceanic9admin.yourwebhosting.com
Sending IP: 209.59.217.91
From: WORLD HEALTH ORGANIZATION (WHO) <healthcaresupport@who.int>
Subject: URGENT INFORMATION LETTER:COVID-19
Attachment: Xeros_ Scan _ Covid_19_ Urgent_information letter.xls.iso (contains "Xeros_ Scan _ Covid_19_ Urgent_information letter.xls.exe")

GuLoader payload URL:
https://drive.google.com/uc?export=download&id=1z9rDpAG9J7v4gYIKssrMvqs10iRFm4tI

Intelligence


File Origin
# of uploads :
2
# of downloads :
95
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-04-14 09:35:33 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
26 of 31 (83.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe b33804d1bcadb3c28baad638d82f7510ab66451a5a602978dfa8f629e6bdca05

(this sample)

  
Delivery method
Distributed via e-mail attachment

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments