🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 14e1a2dfd4db21e08397eb429028ef7f42917c27e07ed814ceb218bd797749c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 14e1a2dfd4db21e08397eb429028ef7f42917c27e07ed814ceb218bd797749c4
SHA3-384 hash: 6c08470c70875fe1824a8c7486beb47b9f89ffd24382fbb094e093abcae8a36785fbe04d99236b12649863d502473ab2
SHA1 hash: 21291fba8eff2d55742b51c1feae913a4b5d3c49
MD5 hash: 7985572b248584f90cc87d2da6e31a72
humanhash: fish-muppet-ten-harry
File name:NOVÉ_ZMLUVNÉ_PODMIENKY-pdf.img.iso
Download: download sample
Signature GuLoader
File size:1'900'544 bytes
First seen:2026-05-20 17:23:13 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 24576:C7Nmx2mKjuV1J7D+epD86fQr0SPdah3ce32ynVy1ZsJOx9nI1:QNmxSjuV1JPTf0jkKy2yVy1ZjI1
TLSH T1A39523A67162C823E5D01370D5966AFF0275AC61C9525B0BB3AD3F093FB3893CA2F615
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter TomU
Tags:GuLoader iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
CH CH
File Archive Information

This file archive contains 15 file(s), sorted by their relevance:

File name:vildttllingens.txt
File size:361 bytes
SHA256 hash: 7f269d088bf50862bdb251a78aac72a82a760c0efc179ca61f810f840b402850
MD5 hash: 6dd7a68900bbafeef18f9ce76609e9e6
MIME type:text/plain
Signature GuLoader
File name:kanaliserende.Ski
File size:545'158 bytes
SHA256 hash: dc28130d3176baf1b6e8f45a166b836e820946a8b08983912813a5e1ad2cb7f7
MD5 hash: 93c54b5e2673abe51500a15718f663bb
MIME type:application/octet-stream
Signature GuLoader
File name:Singerie21.bau
File size:147'523 bytes
SHA256 hash: 69209328af6a5b78a66597dce39ba57691a6611d84f892cb71ae22747e24e52d
MD5 hash: 78241f3b833b51ce38fa55cf256cf470
MIME type:application/octet-stream
Signature GuLoader
File name:suppositions.mor
File size:1'918'671 bytes
SHA256 hash: 474c8bc32bbe33b1a474f412ce3f6b43174df13712a4a899c8f33c1cd67ca91d
MD5 hash: 27017383bfd20bb45ca01334885e6a68
MIME type:application/octet-stream
Signature GuLoader
File name:disproportioneres.ini
File size:483 bytes
SHA256 hash: 4495798222605cd51bf89fe4ee44c0b66ac30dd1a6d528308975e0ad1f7cd049
MD5 hash: 2693014303d4aa64022fa7291ab97eab
MIME type:text/plain
Signature GuLoader
File name:sobersidedly.txt
File size:346 bytes
SHA256 hash: 65eb59d72290cb9b198f6628e2a764c6371e9be0df66c98c297eb22b6e7ced66
MD5 hash: 70d4ea8353e2e24f222723e00e1b1dc2
MIME type:text/plain
Signature GuLoader
File name:yareta.jpg
File size:38'438 bytes
SHA256 hash: 58c0839ab8b79d4850d88f6380909e1c39769009508f0020418c15cbe1a871f4
MD5 hash: cbe8487b7e432a3e78df6ae96a91022c
MIME type:image/jpeg
Signature GuLoader
File name:Kontrolleringerne.hov
File size:6'272'332 bytes
SHA256 hash: cf004385f3f8497e6b19e59dd9f36ffe7b6072922cec8c56ea7a5147de466a83
MD5 hash: 234abe62ec284e204d45061f49d1a939
MIME type:application/octet-stream
Signature GuLoader
File name:spejlggenes.cha
File size:6'785'075 bytes
SHA256 hash: de4b90c67a7c805654daf11b74f23002e6b682b204f6e1d2826fb448bdd6f585
MD5 hash: 471e6571980bee03c9f237de744a0894
MIME type:application/octet-stream
Signature GuLoader
File name:Tnkbare.kan
File size:2'445'930 bytes
SHA256 hash: c5b9318f81b2d6dd857aa39171e1d78718958a2aa67fced6dbc9e7989f49a6c4
MD5 hash: 243c5ae99367f6a721a2bc2f5f6624f4
MIME type:application/octet-stream
Signature GuLoader
File name:powders.txt
File size:315 bytes
SHA256 hash: 5ecc772b8f7ae777cd1df223724c0cd31b5693a12c177ab77d5ed13d2b8b5736
MD5 hash: 3211011141a14526fdded7d6100ed7a8
MIME type:text/plain
Signature GuLoader
File name:NOVE_ZML.BAT
File size:1'330'355 bytes
SHA256 hash: cbc25c50520bc41b95caece3d32a92114aca34cffd8fda533b3e9fe2959fdb87
MD5 hash: 1981a7b5d8b0c42da3d8ccc70518b740
MIME type:application/x-dosexec
Signature GuLoader
File name:revoksets.jpg
File size:53'075 bytes
SHA256 hash: fe9720910ef0f60def919fbe5066bc898f86f65f7c7c1c68dfdad9da4e24821c
MD5 hash: 7f0e79823cf6d6c639f68d713a904f66
MIME type:image/jpeg
Signature GuLoader
File name:centuplicating.jpg
File size:4'327 bytes
SHA256 hash: 03c300a496537d56bb62bc1935518f67d8ba7fc52d3fd6711ca3ba2ff2dc308b
MD5 hash: 4c971260589e88672fe354aa20fb9fbe
MIME type:image/jpeg
Signature GuLoader
File name:Sinologers.Non
File size:74'840 bytes
SHA256 hash: 869dc38e9847d484c9bf2ed1076134457d380d48ee90ca9be0e11bcda3b8de58
MD5 hash: 75f1913d75ff76edd28a7b78309ce0d2
MIME type:text/plain
Signature GuLoader
Vendor Threat Intelligence
Malware configuration found for:
Archives NSIS
Details
Archives
extracted archive contents
NSIS
extracted archive contents
Verdict:
Malicious
Score:
70%
Tags:
shellcode
Verdict:
Malicious
File Type:
iso
First seen:
2025-07-01T07:22:00Z UTC
Last seen:
2026-04-14T13:02:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2025-07-01 10:53:05 UTC
File Type:
Binary (Archive)
Extracted files:
15
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso 14e1a2dfd4db21e08397eb429028ef7f42917c27e07ed814ceb218bd797749c4

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments