🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 091647849e67337dc0ae30c6e6eea22b5660906db387ac0bfdc2700cb9c8402a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 091647849e67337dc0ae30c6e6eea22b5660906db387ac0bfdc2700cb9c8402a
SHA3-384 hash: c953634b743efc7e183dec1ae2e4de594905d8008eea1541bb9a83b471876e86d135b9e209ce78237547bffc6c7b891a
SHA1 hash: c68cd8102c102103f5b6f211b6b00fca6a0e02e9
MD5 hash: e280859dd4a2d84744e9533c4589eefe
humanhash: johnny-bluebird-hamper-hamper
File name:PaymentAdviseSwift0285.rar
Download: download sample
Signature GuLoader
File size:246'479 bytes
First seen:2026-02-17 07:16:19 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:6TbJsdXlkRgQGFvZ6DprPDyZ6X7WKnqGoKpVh4jq2JjYKwUd9gaNZ4:AlsdXlkRgQ8IDpr4eqbKpn2f1dW2K
TLSH T1843423BC8C46B4378D600F1E68383B9524AD1CD478F3B41B57477A9ABE7AB599634330
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter lowmal3
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
93
Origin country :
DE DE
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:Brndingerne.aff
File size:85'586 bytes
SHA256 hash: 4e7dc2cbc23bdd24f5e2f83e2f7b4a3a418549cddd95071537076af3d35ad14b
MD5 hash: 8e2326f6200855c83bac9db42ef452b3
MIME type:application/octet-stream
Signature GuLoader
File name:System.dll
File size:12'288 bytes
SHA256 hash: 014f1dfeb842cf7265a3644bc6903c592abe9049bfc7396829172d3d72c4d042
MD5 hash: 12b140583e3273ee1f65016becea58c4
MIME type:application/x-dosexec
Signature GuLoader
File name:modern-wizard.bmp
File size:26'494 bytes
SHA256 hash: 3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
MD5 hash: cbe40fd2b1ec96daedc65da172d90022
MIME type:image/bmp
Signature GuLoader
File name:Grobrian.Ble
File size:138'721 bytes
SHA256 hash: c99c2cf846f3b633515f59d43006119c17ea42415cec2c1928219f6cd56e69b7
MD5 hash: 439146260d9e2ca9f58ea9df99960907
MIME type:application/octet-stream
Signature GuLoader
File name:PaymentAdviseSwift0285.bat
File size:266'647 bytes
SHA256 hash: 12db648c3d516bb4210f37388077273757ea792168a6c32a9c0210cbfc7c01f9
MD5 hash: c0214c5ac40753c905e4ecf9c4a8b48e
MIME type:application/x-dosexec
Signature GuLoader
File name:Propless.Fra
File size:172'543 bytes
SHA256 hash: 884ed5c7146a3d42c464acd9cfa019d201d8e1d268043394a91469b5b988642b
MD5 hash: 86f74ca4e9aa3dc47aa4b3b627486e2f
MIME type:application/octet-stream
Signature GuLoader
File name:nsDialogs.dll
File size:9'728 bytes
SHA256 hash: b2699fdfdab6a018fcc972806d12f71972de1861660bb6578935d62b1da06504
MD5 hash: 3cea4c9994912d8f3c3e8b6a814e810e
MIME type:application/x-dosexec
Signature GuLoader
File name:postanvisningers.fib
File size:16'110 bytes
SHA256 hash: 6044c8b634066141ecd8c3ed1f55cbb97a7aef4721015d3330dbdc8b03cca9c1
MD5 hash: dfae467b8b2795d4741e263aa556e655
MIME type:application/octet-stream
Signature GuLoader
File name:markrens.sal
File size:64'195 bytes
SHA256 hash: 34ec84085f2016f4a128164de6444e34097cd49f3e1e55419ea7b4e831091321
MD5 hash: 29b1948f527f0e80a50ba378845400a2
MIME type:application/octet-stream
Signature GuLoader
File name:subjektsprdikaters.tes
File size:2'853 bytes
SHA256 hash: 7eae2cf23a7c794125baf87e0ad08b36eb686cc7c5d4a6072c3d44499c4a5f4b
MD5 hash: 598d33d3e6f87699d491912c520e13cb
MIME type:application/octet-stream
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole guloader installer installer installer-heuristic masquerade microsoft_visual_cc nsis soft-404 unsafe
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Rar Archive
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2026-02-16 11:12:06 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
21 of 36 (58.33%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:guloader family:phantom_stealer collection discovery downloader installer persistence spyware stealer
Behaviour
outlook_win_path
outlook_office_path
Uses Task Scheduler COM API
Suspicious use of WriteProcessMemory
Suspicious use of SetWindowsHookEx
Suspicious use of FindShellTrayWindow
Suspicious use of AdjustPrivilegeToken
Suspicious behavior: MapViewOfSection
Suspicious behavior: EnumeratesProcesses
Modifies registry class
Modifies data under HKEY_USERS
Enumerates system info in registry
Checks processor information in registry
NSIS installer
Program crash
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Drops file in Program Files directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of NtCreateThreadExHideFromDebugger
Looks up external IP address via web service
Contacts third-party web service commonly abused for C2
Adds Run key to start application
Accesses Microsoft Outlook profiles
Reads user/profile data of web browsers
Loads dropped DLL
Executes dropped EXE
Phantom_stealer family
PhantomStealer
Guloader,Cloudeye
Guloader family
Detects PhantomStealer payload
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 091647849e67337dc0ae30c6e6eea22b5660906db387ac0bfdc2700cb9c8402a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments