🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 39b971a72423d91ae285fc68c18d51011a39929059cbb77b25ec2484d5b6e32e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 39b971a72423d91ae285fc68c18d51011a39929059cbb77b25ec2484d5b6e32e
SHA3-384 hash: 36e0cac01d17ca86a29c5dd44f7835b864587bd0dfb227a836a57035aa4220b32700a22e41ac0e03c0d2c73d469c58c2
SHA1 hash: 35de187f661f3340980529bf80f2aa96eb868052
MD5 hash: 8ea0900e6349738aa8bd6a104f3ff7d6
humanhash: montana-violet-magazine-sink
File name:Zmienione warunki-pdf.js
Download: download sample
Signature GuLoader
File size:30'261 bytes
First seen:2026-09-10 15:15:56 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:6PGbLlhAL97zQ0tr8sGj7drgiBohNx+VXFwob:YWkLqg8P7aiK6FFb
TLSH T106D26C55DD1614BE0B46B68C7CE64655CAAB43218413C131E6BECF1E20C9AACEB784EF
Magika javascript
Reporter abuse_ch
Tags:GuLoader js

Intelligence


File Origin
# of uploads :
1
# of downloads :
99
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-10T03:41:00Z UTC
Last seen:
2026-09-10T11:38:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Sigma detected: WScript or CScript Dropper
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Drops file in Windows directory
Badlisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments