MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e031beb4c230faf0d895f0d40e5063d56c41d11cf6208a531a35176cd76e3a41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: e031beb4c230faf0d895f0d40e5063d56c41d11cf6208a531a35176cd76e3a41
SHA3-384 hash: 1fb6e441e4ff05cbff8b8e0164affa15433d40f32bb019746b341d8f06c178d592c4174781610cb596e9f630b52d7813
SHA1 hash: bf75821905242bd4e293840bc54af00a98bf4067
MD5 hash: 76a8fbaba3569e761e4025281f5960c8
humanhash: cat-maine-violet-music
File name:Recovery@customer.exe
Download: download sample
Signature GuLoader
File size:77'824 bytes
First seen:2020-04-28 04:57:50 UTC
Last seen:2020-04-28 05:59:59 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash fb067913667aa9b969fc01a831221366 (1 x GuLoader)
ssdeep 768:CT71Lope7qOsAVQKJrByNZ+k1BliQwic3hJ/62a:i18pNOsjK7mZ+kMQwic/ij
Threatray 626 similar samples on MalwareBazaar
TLSH E3732C23788489F3E0198EB11AA1CBED1B4A7C715F01AD47BD853B5D2E3CE149690BF6
Reporter JoulK
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe e031beb4c230faf0d895f0d40e5063d56c41d11cf6208a531a35176cd76e3a41

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments