MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 14


Intelligence 14 IOCs YARA 17 File information Comments

SHA256 hash: 0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3
SHA3-384 hash: 0eba9bcd369c6a5e58c008d22ed6f37150a25e10d7033160e4540febcf7a0da70b603e8e02e5c1145046f6a98dfc222a
SHA1 hash: 9cbe5798ca562db8bd9bb63edd11ddb1d1e637f6
MD5 hash: 7537d649c3ec62d6de4f4397639abe9d
humanhash: lamp-saturn-mobile-hot
File name:LPO 2623594699.exe
Download: download sample
Signature GuLoader
File size:348'224 bytes
First seen:2026-07-31 05:49:58 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ced282d9b261d1462772017fe2f6972b (128 x Formbook, 124 x GuLoader, 72 x RemcosRAT)
ssdeep 6144:W9X0GN6Bo9PMbSDWUtnKMD6PEvM0xGhJmN+7qjFVIeJGbAu0+1D0GeablKAYQfN6:Y0MOo9PM+vtA9UfNez1feabcR86
TLSH T1457412092BA0D0A7CC1A0A728CF2AE765FF44E10605643075788BB7F7D637D6B62E647
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 6270b46692866030 (1 x Formbook, 1 x GuLoader)
Reporter lowmal3
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Unaccessibly
Issuer:Unaccessibly
Algorithm:sha256WithRSAEncryption
Valid from:2026-07-19T02:52:02Z
Valid to:2027-07-19T02:52:02Z
Serial number: 50a7557615ad24dd5fe0772c0a4ebb235e736b60
Thumbprint Algorithm:SHA256
Thumbprint: dc634e878bc81223ce2f42e24a3c6fa7f3acaa9e289a12fe3952d803bb755dc3
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
160
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
formbook
ID:
1
File name:
b803e09b-74ab-93d4-12d5-c9afc2fb7b95.eml
Verdict:
Malicious activity
Analysis date:
2026-07-30 15:23:32 UTC
Tags:
arch-exec attc-arch attachments stealer formbook xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a window
Creating a file in the %temp% subdirectories
Searching for the window
Creating a file
Delayed reading of the file
Deleting a recently created file
Unauthorized injection to a recently created process
Restart of the analyzed sample
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
installer installer microsoft_visual_cc nsis signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-30T02:53:00Z UTC
Last seen:
2026-07-31T02:38:00Z UTC
Hits:
~100
Result
Threat name:
GuLoader, FormBook
Detection:
malicious
Classification:
troj.evad.spyw
Score:
100 / 100
Signature
AI detected suspicious PE / MSI digital signature
Antivirus detection for URL or domain
Binary is likely a compiled AutoIt script file
Found direct / indirect Syscall (likely to bypass EDR)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queries Google from non browser process on port 80
Queues an APC in another process (thread injection)
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Yara detected FormBook
Yara detected GuLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1950473 Sample: LPO 2623594699.exe Startdate: 31/07/2026 Architecture: WINDOWS Score: 100 37 www.mobilik.xyz 2->37 39 www.darkriver.xyz 2->39 41 23 other IPs or domains 2->41 53 Suricata IDS alerts for network traffic 2->53 55 Antivirus detection for URL or domain 2->55 57 Multi AV Scanner detection for submitted file 2->57 61 7 other signatures 2->61 10 LPO 2623594699.exe 1 38 2->10         started        signatures3 59 Performs DNS queries to domains with low reputation 39->59 process4 file5 33 C:\Users\user\AppData\Local\...\System.dll, PE32 10->33 dropped 35 C:\Users\user\AppData\...\aphidolysin.skp, COM 10->35 dropped 13 LPO 2623594699.exe 6 10->13         started        17 LPO 2623594699.exe 10->17         started        process6 dnsIp7 49 drive.google.com 142.251.45.206, 443, 49872 GOOGLE-GoogleLLCUS United States 13->49 51 drive.usercontent.google.com 142.251.45.65, 443, 49873 GOOGLE-GoogleLLCUS United States 13->51 75 Modifies the context of a thread in another process (thread injection) 13->75 77 Maps a DLL or memory area into another process 13->77 79 Queues an APC in another process (thread injection) 13->79 81 Found direct / indirect Syscall (likely to bypass EDR) 13->81 19 N9Xw2f0o.exe 13->19 injected 22 LPO 2623594699.exe 13->22         started        signatures8 process9 signatures10 63 Binary is likely a compiled AutoIt script file 19->63 24 write.exe 13 19->24         started        process11 signatures12 65 Tries to steal Mail credentials (via file / registry access) 24->65 67 Tries to harvest and steal browser information (history, passwords, etc) 24->67 69 Modifies the context of a thread in another process (thread injection) 24->69 71 3 other signatures 24->71 27 bofqsSRrZ.exe 24->27 injected 31 firefox.exe 24->31         started        process13 dnsIp14 43 onstatic-pt.setupdns.net 81.88.57.70, 49927, 49928, 49929 REGISTER-ASIT Italy 27->43 45 veteransixes.org 66.116.229.205, 49931, 49932, 49933 ORACLE-BMC-31898-OracleCorporationUS India 27->45 47 14 other IPs or domains 27->47 73 Binary is likely a compiled AutoIt script file 27->73 signatures15
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-30 15:45:33 UTC
File Type:
PE (Exe)
Extracted files:
11
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:formbook family:guloader discovery downloader installer rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Family: Formbook
Family: Guloader,Cloudeye
Formbook payload
Unpacked files
SH256 hash:
0cc87edf5dd17fe02cb5fa8925087374dde0f3a2de206f726f2c98d2f193f6c3
MD5 hash:
7537d649c3ec62d6de4f4397639abe9d
SHA1 hash:
9cbe5798ca562db8bd9bb63edd11ddb1d1e637f6
SH256 hash:
269d232712c86983336badb40b9e55e80052d8389ed095ebf9214964d43b6bb1
MD5 hash:
34442e1e0c2870341df55e1b7b3cccdc
SHA1 hash:
99b2fa21aead4b6ccd8ff2f6d3d3453a51d9c70c
SH256 hash:
e664756ea6bfb01787ee6dfe299f1e1cc52b0453759771124c9359cb3cf79cb4
MD5 hash:
602d953c391a05d2be162a661962c598
SHA1 hash:
794b83002517dca3a017337946d39df55646e3e0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:FormhookB
Author:kevoreilly
Description:Formbook Anti-hook Bypass
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:NSIS
Author:kevoreilly
Description:NSIS Integrity Check function
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Win_FakeInstaller_PythonShellcodeLoader_Crepectl_2026
Author:SixHands
Description:Detects the analyzed fake installer sample using .key config, XOR key, and Python/fiber shellcode loader traits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments