MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b508273bfcc6a902441e4a865879fce86cba3187773faf9838d8145a0deece5a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b508273bfcc6a902441e4a865879fce86cba3187773faf9838d8145a0deece5a
SHA3-384 hash: e5ce523d92e737c8ce2a17c353e74b00ca7f2c19aad599f51bfe75ee6e62d8dcc29b52563d5a8898fcb7afeb4ae92221
SHA1 hash: 605c0b7f1885a08c02a4588ebd1c1c6fa361deee
MD5 hash: ef3ab91692db636b0eae5cc6212fbcaf
humanhash: december-oklahoma-carbon-tango
File name:SecuriteInfo.com.Fareit-FXXEF3AB91692DB.1939
Download: download sample
Signature GuLoader
File size:102'400 bytes
First seen:2020-08-03 22:28:33 UTC
Last seen:2020-08-04 05:49:19 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e2567d9a5970ee0ecf05b3270a4b2aa0 (1 x GuLoader)
ssdeep 768:PeCvGt+DV9dsIUuLt2anKd9TgAd0y6IxrJLhMelX4DSkthWU02P/V7s5VGhC:PeQYqTUuhCuF+JL6A4xf0L5VI
Threatray 686 similar samples on MalwareBazaar
TLSH 7AA3C616A5E85229F167DF715D744AEB423C7C3C382EC58B9EF4389E37B2A048624727
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
723
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Hides threads from debuggers
Tries to detect virtualization through RDTSC time measurements
Yara detected GuLoader
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-08-03 18:29:13 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe b508273bfcc6a902441e4a865879fce86cba3187773faf9838d8145a0deece5a

(this sample)

  
Delivery method
Distributed via web download

Comments