General

  • Target

    68f3bf5dd667a67b986f0831811ee9dbe9ad372e54e5566cd09fb76d84d08186.dll

  • Size

    42.4MB

  • MD5

    c498e1267a56d45eaf265e4c892ae879

  • SHA1

    1b796f14bb72c26998275c11643a3ffb6fed4d2d

  • SHA256

    68f3bf5dd667a67b986f0831811ee9dbe9ad372e54e5566cd09fb76d84d08186

  • SHA512

    a71b426d3681c4f7f079e2f847f6d1dc30fd7c746dea3580be0bb2a1a8198895dca7ff2d93325ead83e265b89534282def886106b4fe526a3d18470c81f016f4

  • SSDEEP

    393216:cBkHQAgLm3eYXcR4Gx8j7p17dSfqAUiNavFFLCrfsonAc+y87Wn:c7yBcipAUP9MdAcv8y

Malware Config

Signatures

  • Guloader family
  • Guloader payload 1 IoCs
  • M00nD3v Logger payload 1 IoCs

    Detects M00nD3v Logger payload in memory.

  • M00nd3v_logger family
  • HTTP links in PDF interactive object 1 IoCs

    Detects HTTP links in interactive objects within PDF files.

  • Unsigned PE 1 IoCs

    Checks for missing Authenticode signature.

Files

  • 68f3bf5dd667a67b986f0831811ee9dbe9ad372e54e5566cd09fb76d84d08186.dll
    .dll windows:10 windows x64 arch:x64


    Headers

    Sections