MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3bbab3b78373c6545395824227850d304764369dd339283500bd34f80cb949e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: e3bbab3b78373c6545395824227850d304764369dd339283500bd34f80cb949e
SHA3-384 hash: 968f46d11928dbb16bdf96ebfd2f110dda53a94b0bf94e51dff91ee47d2a756700644dd63c4367af0a8d19f477e669b8
SHA1 hash: 3242b48a6d6320adc513a2958ee6f9847552a30e
MD5 hash: 464de23bd99b9b36f097e9416ef0f54a
humanhash: thirteen-tango-oregon-massachusetts
File name:SecuriteInfo.com.Trojan.DownLoader33.32199.28416.7191
Download: download sample
Signature GuLoader
File size:106'496 bytes
First seen:2020-04-15 20:49:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f515caa0b268750b905d768646d3df0a (2 x GuLoader)
ssdeep 768:1+8b9WjdHUxJVcrSIZ3uxLQ1aao7/0CrIo2afhF+wF6/lB8W6:N9W5HUx3crSSexUUN7//rF2aX+46w
Threatray 176 similar samples on MalwareBazaar
TLSH B5A3F8517AA0FF41D84A0E7169B2CEA80A267D349D9073077AC57E7F39B11D0BB22F52
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments