MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d79b2421672e269c39ae41a6504e0d28f9b76e3f57d8c1c4c502ad0b9387a39e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: d79b2421672e269c39ae41a6504e0d28f9b76e3f57d8c1c4c502ad0b9387a39e
SHA3-384 hash: a0235d00b695da15165d373b670c2dcdab0263caeed1b4e49edb21886d828b6de154a4e0b72d182261376ac0368da508
SHA1 hash: a1434bcff813e06dced293c1eac0af03594af75f
MD5 hash: 1f5867bce6774bae8df4e519fec5bf73
humanhash: robert-football-muppet-fix
File name:INQUIRY NOV PO.JPEG .scr
Download: download sample
Signature GuLoader
File size:69'632 bytes
First seen:2020-11-05 18:50:23 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b3002d3d7627db8ba8abd663c167b810 (1 x GuLoader, 1 x Loki)
ssdeep 768:UkRRQ1Zji8myZglTbRxhQFHFVPF88PW4EW:3Y1QXZjQFHGl4J
Threatray 572 similar samples on MalwareBazaar
TLSH 01634A57E4C915A3DF170EB60E6DC77C80CB5E1439EABA0BE5283FAF25716614C08A4E
Reporter abuse_ch
Tags:GuLoader scr


Avatar
abuse_ch
GuLoader payload URL:
https://axgvbnyote.xyz/test_vsqvTjqhKW86.bin
https://od.lk/d/NzhfMjExNTM3Mjlf/test_vsqvTjqhKW86.bin
https://www.termorolne.rs/png/test_vsqvTjqhKW86.bin

Intelligence


File Origin
# of uploads :
1
# of downloads :
175
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Threat name:
Win32.Trojan.Vebzenpak
Status:
Malicious
First seen:
2020-11-05 18:52:08 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Unpacked files
SH256 hash:
d79b2421672e269c39ae41a6504e0d28f9b76e3f57d8c1c4c502ad0b9387a39e
MD5 hash:
1f5867bce6774bae8df4e519fec5bf73
SHA1 hash:
a1434bcff813e06dced293c1eac0af03594af75f
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments