MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3597e200f4430fc1d6bd0ad657e24824e32b9bbd59ad5f948a9a1bfbecca991. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b3597e200f4430fc1d6bd0ad657e24824e32b9bbd59ad5f948a9a1bfbecca991
SHA3-384 hash: 35b868c1d896cba1d27767da07e7486a7668d1bfaa95e5c12a7e016e0da576512096f957d8f5897977e30f3869e7b926
SHA1 hash: 42d8f1d03eff978cd9c364d153a71a0a5ae0187a
MD5 hash: 8d5dde17cefc6e0fa2e3dd0b560f5fb8
humanhash: diet-queen-butter-quebec
File name:PO LT18-EIG-006-007-THIENPHU-001.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-04-30 09:29:40 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7102f25f2728ce267ac07a2a9a11eb7b (1 x GuLoader)
ssdeep 768:3xhrBUdaTGl2nFoV0Y6+pbMMFTrTMg240/zGmciaYnNHNYeBJIsLHv+kNTU8ubf:3XydOs2wgYTfGG8aYnNtY2WCTtsf
Threatray 169 similar samples on MalwareBazaar
TLSH AC93D7886FF8E077EAA849F20753459420D82F37FC611A2772897A6E7679790C0127F7
Reporter jarumlus
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef
MSVBVM60.DLL::__vbaFileOpen

Comments