MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eef03fc251a9738be52ecd757a51eab6cc17c0d181621ae9431a7f88a1b42ed6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: eef03fc251a9738be52ecd757a51eab6cc17c0d181621ae9431a7f88a1b42ed6
SHA3-384 hash: ee9660ffd01975b06092a1c50cd5ab2622c14c0e9a23728c9085d3c77d9e475acca84af107b8eb8656d67e654e5b959e
SHA1 hash: f23a1e2413a2862b95079dc4e94e6730eb07f539
MD5 hash: b511e874c3a31b41f8d9f05fb91d5cb7
humanhash: twenty-alpha-ten-fifteen
File name:eef03fc251a9738be52ecd757a51eab6cc17c0d181621ae9431a7f88a1b42ed6
Download: download sample
Signature GuLoader
File size:561'152 bytes
First seen:2020-03-23 15:59:30 UTC
Last seen:2020-03-23 16:18:30 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 4f428caddf4d41456a6d510711bf3410 (1 x GuLoader)
ssdeep 6144:n9/djXq6d5Z+nxS7D3lRPjrxoKivJqaC3LxUJ505vJ/ke4mqmBk17jy0Bl1RgCji:JtdT4xS7jLiKIJy39trimqmixyqpxjb
Threatray 105 similar samples on MalwareBazaar
TLSH 11C4591A447BC713E4873FF1B48D20DDEEB329C92E4C53EAA27012E627694E6D645C0B
Reporter Marco_Ramilli
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe eef03fc251a9738be52ecd757a51eab6cc17c0d181621ae9431a7f88a1b42ed6

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments