MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4a6bde59452ed3c565535321cf37bd40fd1ad7a547ae2dddb555a3bfdfff236. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d4a6bde59452ed3c565535321cf37bd40fd1ad7a547ae2dddb555a3bfdfff236
SHA3-384 hash: 76e8ade421b70d3dfe92681b327b97adb7afaec351ba5d481c8ab659e0bbd977b9cbd7bd88604b5c5045c9c9d10c3313
SHA1 hash: c44cc76d78cf7020ac2e68b85ac8f8ee8a025d40
MD5 hash: 5edf71919c37e6b8dd1bfde57ee068ba
humanhash: eleven-fillet-blue-cold
File name:SecuriteInfo.com.generic.ml.6891
Download: download sample
Signature GuLoader
File size:102'400 bytes
First seen:2020-08-03 09:35:52 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0962aa2a1407ebb324100f1804250568 (1 x GuLoader)
ssdeep 768:VlPUVYm29dd0dgLmPWKMakIAadvkhLDYeu1fo94gzKlx2P/kC7sBTy:V1UbR4UW1akxaNkR4fA48+xlBT
Threatray 5'283 similar samples on MalwareBazaar
TLSH 90A3E716A5E84229F27BDFB15D7447E7413C7D38382EC58B9DE4396F33B29088621A27
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
139
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Sending a UDP request
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
56 / 100
Signature
Hides threads from debuggers
Tries to detect virtualization through RDTSC time measurements
Yara detected GuLoader
Behaviour
Behavior Graph:
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-08-03 08:28:49 UTC
AV detection:
35 of 48 (72.92%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of SetWindowsHookEx
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe d4a6bde59452ed3c565535321cf37bd40fd1ad7a547ae2dddb555a3bfdfff236

(this sample)

  
Delivery method
Distributed via web download

Comments