🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b71f21cbdaadb8658ac8940a4709df3f23dfc9fa6e784d50ebbc7a7888469e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 1b71f21cbdaadb8658ac8940a4709df3f23dfc9fa6e784d50ebbc7a7888469e2
SHA3-384 hash: 98b9e339be083c9c2b368d44648d066d722b483fade03b2caf20d5c09243179a754bdf9b14d2fc6951a693a0b2faeb90
SHA1 hash: d45a7cfa756ccac0d2bee7a2f8fd69f21ef17c65
MD5 hash: cbe72e93c04a891198f9dc0899244b3a
humanhash: solar-may-romeo-gee
File name:SKCMLT17622520986618485758458589457.bat
Download: download sample
Signature GuLoader
File size:6'977 bytes
First seen:2025-12-01 14:37:46 UTC
Last seen:2026-05-20 17:25:11 UTC
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 192:kBqWlLlYZHjJvtj6uaptnOna3cdIkiivpJM:Mqa+Hj36uaznOaqIQvXM
TLSH T10DE12C02BD93717A7424424B7C1DD3CC389570D70A3216B831AF7639B9EBA28732D05D
Magika txt
Reporter lowmal3
Tags:bat GuLoader

Intelligence


File Origin
# of uploads :
3
# of downloads :
89
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
PLAČILNI dokument SI56 Intesa SanpaoloServen.7z
Verdict:
Malicious activity
Analysis date:
2025-11-28 14:52:26 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
xtreme shell sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Connection attempt to an infection source
DNS request
Connection attempt
Sending an HTTP GET request
Creating a file in the %AppData% directory
Sending a custom TCP request
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Query of malicious DNS domain
Sending a TCP request to an infection source
Using obfuscated Powershell scripts
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 obfuscated powershell
Verdict:
Malicious
File Type:
ps1
First seen:
2025-11-28T09:30:00Z UTC
Last seen:
2025-12-03T11:38:00Z UTC
Hits:
~1000
Detections:
HEUR:Trojan.BAT.Obfuscated.gen HEUR:Trojan.Script.Generic
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Early bird code injection technique detected
Encrypted powershell cmdline option found
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Obfuscated command line found
Queries the IP of a very long domain name
Queues an APC in another process (thread injection)
Sigma detected: Potential PowerShell Command Line Obfuscation
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected GuLoader
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1823633 Sample: SKCMLT176225209866184857584... Startdate: 01/12/2025 Architecture: WINDOWS Score: 100 46 bafybeihtmj5jk7lzhmxma6hwwvvwijfch4j2h7d23rjh67ah3h4zw3s7dm.ipfs.w3s.link 2->46 48 r13.c.lencr.org 2->48 50 3 other IPs or domains 2->50 62 Malicious sample detected (through community Yara rule) 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 Yara detected GuLoader 2->66 70 6 other signatures 2->70 9 powershell.exe 18 2->9         started        12 cmd.exe 1 2->12         started        14 svchost.exe 1 1 2->14         started        signatures3 68 Queries the IP of a very long domain name 46->68 process4 dnsIp5 72 Early bird code injection technique detected 9->72 74 Writes to foreign memory regions 9->74 76 Found suspicious powershell code related to unpacking or dynamic code loading 9->76 84 4 other signatures 9->84 17 msiexec.exe 2 7 9->17         started        21 msiexec.exe 9->21         started        23 conhost.exe 9->23         started        78 Suspicious powershell command line found 12->78 80 Obfuscated command line found 12->80 82 Encrypted powershell cmdline option found 12->82 25 powershell.exe 14 16 12->25         started        27 conhost.exe 12->27         started        52 127.0.0.1 unknown unknown 14->52 signatures6 process7 dnsIp8 38 bafybeihtmj5jk7lzhmxma6hwwvvwijfch4j2h7d23rjh67ah3h4zw3s7dm.ipfs.w3s.link 172.64.146.87, 443, 49705, 49709 CLOUDFLARENETUS United States 17->38 40 pki-goog.l.google.com 172.253.124.94, 49706, 49718, 49750 GOOGLEUS United States 17->40 42 r13.c.lencr.org 104.18.21.213, 49708, 49720, 49752 CLOUDFLARENETUS United States 17->42 54 Obfuscated command line found 17->54 56 Hides threads from debuggers 17->56 29 cmd.exe 1 17->29         started        32 msiexec.exe 17->32         started        58 Unusual module load detection (module proxying) 21->58 44 metavasipar.hu 79.172.252.49, 443, 49692, 49707 SZERVERNET-HU-ASHU Hungary 25->44 60 Found suspicious powershell code related to unpacking or dynamic code loading 25->60 signatures9 process10 signatures11 86 Obfuscated command line found 29->86 34 conhost.exe 29->34         started        36 reg.exe 1 1 29->36         started        process12
Threat name:
Script-PowerShell.Trojan.GuLoader
Status:
Malicious
First seen:
2025-11-28 14:07:25 UTC
File Type:
Text
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Batch (bat) bat 1b71f21cbdaadb8658ac8940a4709df3f23dfc9fa6e784d50ebbc7a7888469e2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments