MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b4e79c634347e81ec37de162f5bae756f60cdbfa4b0af7c9a11d25f4a51a3ef6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b4e79c634347e81ec37de162f5bae756f60cdbfa4b0af7c9a11d25f4a51a3ef6
SHA3-384 hash: f215ca2e3ecc39cbd5d6a29260cedd871d0193452ce915439b9ee024ab8b75c64a83178814b85934664a8ab43c79e07a
SHA1 hash: 62c4b3c406b2615b73a4baf63482708212fb40d9
MD5 hash: 5c2790e38e2437cc6f0e5720f73e41a5
humanhash: hot-seventeen-one-bravo
File name:Invoice20376.vbs
Download: download sample
Signature GuLoader
File size:2'202'459 bytes
First seen:2022-08-31 07:46:11 UTC
Last seen:Never
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 6144:H+zm7pgdiiU4fmA0DnWsjDxQSsrk9njQWJkEK4/dhEqBkpq:ezm7pg/U4Naee9Evc
TLSH T199A55DA5199E70E4FD804ECFF3928EB55F7329EE09F21845089B26CF09C92595AB5F30
Reporter abuse_ch
Tags:GuLoader vbs

Intelligence


File Origin
# of uploads :
1
# of downloads :
171
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Result
Threat name:
FormBook, GuLoader
Detection:
malicious
Classification:
expl.evad.troj.spyw
Score:
100 / 100
Behaviour
Behavior Graph:
n/a
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments