SUSPICIOUS — GuLoader.vbs
SUSPICIOUS — GuLoader.vbs is a unknown sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (47/100), attributed to the Wacatac family. 3 of 51 detection engines flagged it.
Identification
- SHA-256:
09ee0840c5d0be078ae14befe4a7e758a7c421635d56f6b24038f6bf51f219eb - SHA-1:
575ded031104f566d97fe305a6a7c51dd61e44de - MD5:
af87821d3cb4f1d72bfb8002437593ec - ssdeep:
6144:eOZOV5pzobkxPW94sbMACVpNXVrd4lhKZrIvdjGPhhAru:evnJx8kdpN29Ih7 - TLSH:
T1A2450911704E76A6DBFC9F4E11B6680C2E232BCF6074D6E1B5589AE0D818C2095CBDDB - Submitted as: GuLoader.vbs
- File type: unknown · Size: 276246 bytes
- Verdict: suspicious (47/100) · Family: Wacatac
Detections (3 of 51 engines)
- Microsoft Defender: Trojan:Script/Wacatac.B!ml
- Emsisoft (Emergency Kit): Trojan.GenericKD.80998952
- Kaspersky (KVRT): HEUR:Trojan.VBS.SAgent.gen
Why this verdict
The suspicious score of 47/100 is the fusion of 1 weighted signal:
- Microsoft Defender flagged Trojan:Script/Wacatac.B!ml (rule
Trojan:Script/Wacatac.B!ml) - engine signal, weight 0.55, confidence 0.85
File paths
- c:\windows\
More Wacatac samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report