MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 26a0e6f7a66c9eeb9c129327ebe3ab49ad39212c644e7f4ac86f54eb69846456. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: 26a0e6f7a66c9eeb9c129327ebe3ab49ad39212c644e7f4ac86f54eb69846456
SHA3-384 hash: 2b9df8fb38f7cd93dfa05c57773e91da40399d1d7b0c840d963d3f4d487c9fe2281240d16134eb047a130723c0f3100e
SHA1 hash: d3b03a887c3da72355ade225cbf38dc69eb65692
MD5 hash: 8260c941e4016570e4bd7b5cfa819f99
humanhash: cola-spaghetti-massachusetts-sink
File name:Final 2025 Annual Leave Compliance Reportpdf.gz
Download: download sample
Signature GuLoader
File size:877'051 bytes
First seen:2025-09-25 21:08:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 24576:kydURHTLfqNFQrU5KZCSmFX9U2WpSkG/Uiv:eRHPqkrUTn5cpSkG1
TLSH T121152300FA33A97917A13B8003747042156573C7B2871F0E5E5A7DCA66EC26B36BBBD9
Magika zip
Reporter cocaman
Tags:gz zip


Avatar
cocaman
Malicious email (T1566.001)
From: "HR Department <miya@servicedive.com>" (likely spoofed)
Received: "from quill.servicedive.com (quill.servicedive.com [94.156.175.118]) "
Date: "25 Sep 2025 21:07:14 +0000"
Subject: "Final Annual Leave Compliance for 2025 (Batch 2)"
Attachment: "Final 2025 Annual Leave Compliance Reportpdf.gz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
CH CH
File Archive Information

This file archive contains 25 file(s), sorted by their relevance:

File name:Prostaglandin.txt
File size:374 bytes
SHA256 hash: 5456218cfd5fba066451ad0ddc75cecc07eff13ac39d1e8d3cd9a273b6aedc54
MD5 hash: 5df32fddc7baaee13f55df3b1d5c2555
MIME type:text/plain
Signature GuLoader
File name:udbenes.jpg
File size:63'583 bytes
SHA256 hash: 8fd1af367d78cf3a967bc01aec35703b99ddf367612ca6c149d7a58281e55084
MD5 hash: d3ce90edf847ae88581a36caa32afd7b
MIME type:image/jpeg
Signature GuLoader
File name:Chemistries.txt
File size:502 bytes
SHA256 hash: 1f453d4b1697afa667dbd325332677240c3a7bdcb187184c4700a8886d0e88ea
MD5 hash: dccf2b5a2501f2bb0117de662c5635dd
MIME type:text/plain
Signature GuLoader
File name:scan0925.bat
File size:1'137'096 bytes
SHA256 hash: 8e6b8cff477fe728413cd3547e19399053b80007d8a22280ae806a43c90e3d39
MD5 hash: 6c850692db8d5b590c88b2fc3794d25f
MIME type:application/x-dosexec
Signature GuLoader
File name:containerhavnen.jpg
File size:18'372 bytes
SHA256 hash: 403edff15e8256a67a63ed0786b6e94359e7d89b057171b0ddf100517d8353aa
MD5 hash: 7fc04f46360faf5d91fb7c89c6d4e72a
MIME type:image/jpeg
Signature GuLoader
File name:phemic.ini
File size:213 bytes
SHA256 hash: 66c8a7ea5fbdae0b6a89319e2a5f83ea1c11047482250cd40a6c4ffe522d65a2
MD5 hash: b175b5d5a56c1c7f0a3a5ce297269226
MIME type:text/plain
Signature GuLoader
File name:udsvings.txt
File size:571 bytes
SHA256 hash: a0bfd3d9686489cfa12faf9e4d2c9ecb7ef74cf43c9e248ceb6c7d904cff99e0
MD5 hash: f09af6a653856a34d2cc05d3aca40f2b
MIME type:text/plain
Signature GuLoader
File name:System.dll
File size:12'288 bytes
SHA256 hash: b7823a15e7b1866ba3d77248f750b66505859d264cfc39d8c8c5e812f8ae4a81
MD5 hash: a1da6788aeaf78ca4ae1dece8019e49d
MIME type:application/x-dosexec
Signature GuLoader
File name:othilies.prs
File size:847'507 bytes
SHA256 hash: b0e98b6fd603315af349c1f044624ba5cbea457f1364217abd07239da8bf807d
MD5 hash: 34bfa5ae87189eb0e66b7ee1135ebb14
MIME type:application/octet-stream
Signature GuLoader
File name:folkeeventyrenes.txt
File size:466 bytes
SHA256 hash: f976a8ce7d1ef5803d325eb9d537ea63ed33a149be54244f331421bb32362c2a
MD5 hash: 2f71dfe50c331dedf26afa0460c362a2
MIME type:text/plain
Signature GuLoader
File name:toksicitetens.jpg
File size:14'043 bytes
SHA256 hash: ba94b20731631c8cf22dd9bc3c93fc59a075af16bd8ccc8a99c5c53134a0e05d
MD5 hash: 7441792fa8661361cf5fe46d7e3bfd98
MIME type:image/jpeg
Signature GuLoader
File name:Duraspinalis.txt
File size:601 bytes
SHA256 hash: 74ef7e4df2831b1f6c7cdc122ba0d912afc355c2b04f2a445ae0b08e5944fe21
MD5 hash: 95c8912e33dbc6d0d9c968269b8634cd
MIME type:text/plain
Signature GuLoader
File name:arsens.txt
File size:504 bytes
SHA256 hash: f077c2446cbaf5ed10f4023c81d1dd25d0663ec21852ea888155f5c5cfbfb68e
MD5 hash: 87f084bb9af697312b7c64beeb8bd004
MIME type:text/plain
Signature GuLoader
File name:Miljinvesteringens.Emb56
File size:98'772 bytes
SHA256 hash: 2c29aff8c4301432e91de141baea5ae7575874903ed17a30ba79fc69c2434d45
MD5 hash: eaa4297ad55c7c974abf6fb94d809a24
MIME type:application/octet-stream
Signature GuLoader
File name:buketrosernes.god
File size:541'431 bytes
SHA256 hash: 2638cbf2a33ce0a7460b2324a988be0fafbb692507eb73f22a14f65865dd4f78
MD5 hash: 1ced21cdf9c4d75515f25d617c384459
MIME type:application/octet-stream
Signature GuLoader
File name:dimensioneringens.jpg
File size:37'872 bytes
SHA256 hash: 8dd27fbfd51464bf7a34db026357b713f68f1a46168af4447ec7c90b2320c8a3
MD5 hash: cccc1aa7f76b068387903d3e916003a1
MIME type:image/jpeg
Signature GuLoader
File name:vias.ini
File size:294 bytes
SHA256 hash: b19edb8881ec88e4b34c9b66901c0d460c0ac50e4f71c201b60b942ab54df0d6
MD5 hash: 6b5cbee0adb8d234fa4e233c8d61c2a6
MIME type:text/plain
Signature GuLoader
File name:sammenarbejdets.gra
File size:1'574'761 bytes
SHA256 hash: 2328e92d89f663a067c7288b5d181c2088695677714723a6e9a24072a5ae2d2e
MD5 hash: 05a005b60060926ce8a89650bfe3f821
MIME type:application/octet-stream
Signature GuLoader
File name:afsiger.car
File size:1'183'798 bytes
SHA256 hash: b94f8ac3d445eca658a5b45c0878d2f0d44611ecad7249c0be4ec1783ac7e73b
MD5 hash: 2a51c25858d768833124df2ba6dd75e3
MIME type:application/octet-stream
Signature GuLoader
File name:uncompartmentalized.jpg
File size:29'457 bytes
SHA256 hash: d7acdc934f27efed23191ecd4567bf8b76dec80d5a8a2522408036ee1f5778c5
MD5 hash: 251f35a16162871ccc02f07016bb4867
MIME type:image/jpeg
Signature GuLoader
File name:fakturadatoernes.ini
File size:637 bytes
SHA256 hash: c63169abc2aa59b74c36b63065e0ed90826a194dbc3e7d0b50d8e8a7d9bf5b32
MD5 hash: 4f8eee739dcdafb43033c8377ed0dd65
MIME type:text/plain
Signature GuLoader
File name:flowerier.jpg
File size:15'258 bytes
SHA256 hash: 6f06fc7ed59f4183ab4a973ffd0454b4b4f4cd8feff0358f5c87fdef0e72d0c1
MD5 hash: 334f3ef3bf264de257e1b3f3020b7ec4
MIME type:image/jpeg
Signature GuLoader
File name:bredrvet.ini
File size:589 bytes
SHA256 hash: 4ba992864fb65dc89eeb8844de066dbd206bfb1ad758c51f7e1a661c01f11778
MD5 hash: d46b81a7003a881f309f60d2b38b7856
MIME type:text/plain
Signature GuLoader
File name:hmorroidernes.txt
File size:255 bytes
SHA256 hash: 1ca945f5c6bca810908d0e29465de98bc4fbeb313dbd72848c37d3548c24dd9e
MD5 hash: 7b42453a2c7602f8db5fb5d51f83e78a
MIME type:text/plain
Signature GuLoader
File name:Skrslibere.Pop
File size:566'055 bytes
SHA256 hash: 5ee6af1a67a4f261e3714384599617444eba11014e3c419e057daa7d5b4257ad
MD5 hash: c1849ec710b4c1aaa77da38fc80a8bfa
MIME type:application/octet-stream
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole installer microsoft_visual_cc nsis overlay
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
Malicious
File Type:
zip
First seen:
2025-09-26T01:49:00Z UTC
Last seen:
2025-09-26T01:49:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-09-25 21:08:03 UTC
File Type:
Binary (Archive)
Extracted files:
25
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 26a0e6f7a66c9eeb9c129327ebe3ab49ad39212c644e7f4ac86f54eb69846456

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments