MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec1082b523e907a55d05c254dbbfaff4eb96428be90099da529073c12908a1df. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: ec1082b523e907a55d05c254dbbfaff4eb96428be90099da529073c12908a1df
SHA3-384 hash: b85e2f7d16b4ab4be10f72653766e561aa4638b69a5a2ecb082b230deba85da1df5908af645ab911d1194841a436032d
SHA1 hash: 2e224ef77aa0b7b996539200e106b60fe8560849
MD5 hash: 7d35e44ce1bc8524de283f269df43329
humanhash: oklahoma-washington-california-dakota
File name:italias.exe
Download: download sample
Signature GuLoader
File size:94'208 bytes
First seen:2020-05-12 07:35:14 UTC
Last seen:2020-05-13 11:25:25 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash dc1e3906716952299e2988866ec096df (2 x GuLoader)
ssdeep 768:ADxGAMO96wg9reGImjMKuU7DmxaDBO5NUUU3NEqBGq1RQPgOUA:8GBpwZku/xalODkExcR0U
Threatray 69 similar samples on MalwareBazaar
TLSH B2938E1E65C498D3E2688DF135395374C42DBC7618228F4718D8A928AA3FF96F07A35F
Reporter abuse_ch
Tags:CHE exe geo GMX GuLoader


Avatar
abuse_ch
Malspam distributing GuLoader:

HELO: mout.kundenserver.de
Sending IP: 212.227.126.131
From: "Schweizerische Eidgenossenschaft" <info@tinomarx.de>
Subject: Steuerrückzahlung
Attachment: complete__3.xlsm

GuLoader payload URL:
http://185.130.215.62/italias.exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-12 08:12:11 UTC
File Type:
PE (Exe)
Extracted files:
4
AV detection:
24 of 31 (77.42%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of NtSetInformationThreadHideFromDebugger
Checks QEMU agent state file
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe ec1082b523e907a55d05c254dbbfaff4eb96428be90099da529073c12908a1df

(this sample)

  
Delivery method
Distributed via web download

Comments