MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dea51f7f074a8d9b0e30626e11ca4a79de602da24ba64d0222ee1162a5fbb5ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dea51f7f074a8d9b0e30626e11ca4a79de602da24ba64d0222ee1162a5fbb5ba
SHA3-384 hash: bd239606a8688f05836e077024854552824134bf99e2cbead595efacc48f208935f95aab0f7680d15bafcb1192c64b2f
SHA1 hash: 85eb64baa6c9d197e79678a1ea222354ed74a989
MD5 hash: 8ed9d7b0812c0658fb12b6a9d52d3a3d
humanhash: equal-ten-moon-video
File name:89NTb.exe
Download: download sample
Signature GuLoader
File size:217'088 bytes
First seen:2020-04-23 12:21:38 UTC
Last seen:2020-04-23 13:15:23 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 6b5500fc181291931573a22b5dc8cf2b (1 x GuLoader)
ssdeep 1536:xnCA0+uCAGH/W4QM0C2Sy8VjG66iQ8qpFI+YuKrsBfwPTaSRSwvzn0z7wGTr:Rb0+LWptsVtV/qO7QRFGSIz0/wGH
Threatray 290 similar samples on MalwareBazaar
TLSH 8F2418556C78E423C71406302EEAEBB9C34CBDD5D9D5CA0F20907B2BAF33646156662F
Reporter oppimaniac
Tags:GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe dea51f7f074a8d9b0e30626e11ca4a79de602da24ba64d0222ee1162a5fbb5ba

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments