MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc53afba68ddf9c98c411cf1b80701a162683fafffbba9b2ed4dc1041cb5d827. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: fc53afba68ddf9c98c411cf1b80701a162683fafffbba9b2ed4dc1041cb5d827
SHA3-384 hash: fe187b7c84bc5b6d073bfe155f8d544568f033d33e9c7b354533ea2ab48a2c88290baba98644576f9e1b700765b84509
SHA1 hash: faa8d9890e519b6ee86385288e1eb431ac03f4bf
MD5 hash: 45591e66febd4a977e9dc624d7566190
humanhash: enemy-enemy-sierra-diet
File name:SecuriteInfo.com.Win32.Injector.ELOZ.17233
Download: download sample
Signature GuLoader
File size:196'608 bytes
First seen:2020-04-23 11:13:31 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 450594a5dfed38bba360132e3952e138 (1 x GuLoader)
ssdeep 1536:pbTJXPM7xdHv83miVci18eDl+aYAvGuv4aoRH+P9hJxJ+zZJ:pxCVU33fae2Vuv4tRsfuzn
Threatray 820 similar samples on MalwareBazaar
TLSH A3142A406D3498B3C61807306EE6D3BAC2987EE6D9E5C69F2001771BEF7368216A156F
Reporter SecuriteInfoCom
Tags:GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
84
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe fc53afba68ddf9c98c411cf1b80701a162683fafffbba9b2ed4dc1041cb5d827

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments