MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bd2dc10117de45a7e8847214e19e3c03358ae022e1f81219d835b886d2c541b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: bd2dc10117de45a7e8847214e19e3c03358ae022e1f81219d835b886d2c541b9
SHA3-384 hash: e4f2c591ee11c562034b1fe1ccd14d76482edf068a15110aafab9b7533254c33f337604fcb0cc27029c6173cd108c5cf
SHA1 hash: b45083e605bead929648e7f626f51cfe9a3f0fca
MD5 hash: f19162ca4036bc919d91f131cdd1bcec
humanhash: lithium-florida-kansas-eighteen
File name:921b316d2e58a6d525d583ec8020a0b5.exe
Download: download sample
File size:172'032 bytes
First seen:2020-03-26 15:44:05 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:85Qyt+sPt4toVQurwXo5qyrjRFz6WER8TQ0bd6BQA7:O+K8uUYkSjRFzpi8TJ65
Threatray 4'850 similar samples on MalwareBazaar
TLSH F7F3AE32D941C031E1B242B4FA7D0B7B883E0E34729565E6E3B129A46FB44A5F52E35F
Reporter abuse_ch
Tags:exe GuLoader


Avatar
abuse_ch
Payload dropped by GuLoader from the following URL:
https://www.sidinstitute.org/logga/bin_encrypted_1256190.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

4a9a13f14bd2993e98a0d4c29ece15a1e5bc76b1e8b8efc7a0723d4dd2b63329

Executable exe bd2dc10117de45a7e8847214e19e3c03358ae022e1f81219d835b886d2c541b9

(this sample)

  
Dropped by
MD5 921b316d2e58a6d525d583ec8020a0b5
  
Dropped by
GuLoader
  
Dropped by
SHA256 4a9a13f14bd2993e98a0d4c29ece15a1e5bc76b1e8b8efc7a0723d4dd2b63329

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments