🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41a58703b602abae9849b85ee30ad4193831499c3df3ddd5a607bef98d44b53e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: 41a58703b602abae9849b85ee30ad4193831499c3df3ddd5a607bef98d44b53e
SHA3-384 hash: 8ccbe5cacecf9f5ff1496b920a2e96790b142ff4fc0d548a3b763b613f6cc257a04d47c7c1a299c705297ce0b4a07dcb
SHA1 hash: 5c3aeca5b990b8eba04e4712ab1d4990e3a14634
MD5 hash: 426c873d4e56cdfaf652990049222875
humanhash: speaker-beer-bravo-one
File name:WurthXInvoiceX4052616348.rar
Download: download sample
Signature GuLoader
File size:573'036 bytes
First seen:2026-05-21 13:39:10 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:xprTx7AJRdya0jGHp39xhpb3dA4eL8A/bMN/UW5Khaflhz:xNlAJYjGHpNxhpzudgA/usgRjz
TLSH T167C42328297D095A29E7D5C5A0BCC6912F321E33CEAAF1C52D69E1A23BCCD1074F59CC
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Wurth Invoice 4052616348.exe
File size:697'820 bytes
SHA256 hash: b0fceff0ca55741de03d3c37d66b518e2edc3f31a75c8acea4d857397d11740f
MD5 hash: 0270d9f65bf63999240fafabbea1bcab
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
injection uloader virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive installer installer installer-heuristic masquerade microsoft_visual_cc nsis reconnaissance smb
Verdict:
Malicious
File Type:
rar
First seen:
2024-11-19T09:17:00Z UTC
Last seen:
2026-01-28T09:03:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2024-11-19 02:32:22 UTC
File Type:
Binary (Archive)
Extracted files:
7
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
vipkeylogger
Score:
  10/10
Tags:
family:vipkeylogger collection discovery keylogger spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
outlook_office_path
outlook_win_path
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Contacts third-party web service commonly abused for C2
Looks up external IP address via web service
Loads dropped DLL
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Family: VIPKeylogger
Malware Config
C2 Extraction:
https://api.telegram.org/bot7773291387:AAFW0tyP5tccfsSYvPespY2G7aDGr5DPwdk/sendMessage?chat_id=7981072606
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar 41a58703b602abae9849b85ee30ad4193831499c3df3ddd5a607bef98d44b53e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments