MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a6b8d26d298279a62f2a27aa6a8a9b67db22a2195f9e4de3c19dccb0a0f8126. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 12


Intelligence 12 IOCs YARA 9 File information Comments

SHA256 hash: 4a6b8d26d298279a62f2a27aa6a8a9b67db22a2195f9e4de3c19dccb0a0f8126
SHA3-384 hash: 8d5d80be5377f01d0acc94be0427c1982c2400068d6199a01f0be92526f8326506d42e9d3e2787d9b3163ef514f426f5
SHA1 hash: 007386fadca47afbe5632420c46f658a978eb688
MD5 hash: f46329e59f449cdcd96a1d78b4e96f59
humanhash: louisiana-happy-montana-mockingbird
File name:4a6b8d26d298279a62f2a27aa6a8a9b67db22a2195f9e4de3c19dccb0a0f8126
Download: download sample
Signature GuLoader
File size:985'832 bytes
First seen:2026-03-06 15:38:27 UTC
Last seen:2026-04-07 18:39:00 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f4639a0b3116c2cfc71144b88a929cfd (136 x GuLoader, 55 x Formbook, 40 x VIPKeylogger)
ssdeep 24576:RXaVXbFfDTwbaCoMoZ2j7IRUCAm504gmfZoeYCQ:FobVDsmn4j8t04gmmL
Threatray 2'486 similar samples on MalwareBazaar
TLSH T14225230AE0B99463E9F11170043766B6FEBB5F1155A0838BA7343F3F3DB58B1852A693
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon d022d8c8f28f80c0 (44 x GuLoader, 12 x VIPKeylogger, 7 x Formbook)
Reporter adrian__luca
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Mannerly
Issuer:Mannerly
Algorithm:sha256WithRSAEncryption
Valid from:2026-02-26T06:22:42Z
Valid to:2027-02-26T06:22:42Z
Serial number: 2fb21c332607d3ae9c202c0fa6d1fa6528e1af4e
Thumbprint Algorithm:SHA256
Thumbprint: d5dba32536ba750a032bf462a3e795d9ffba6bb80948468dcb3578016e0adc01
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
153
Origin country :
HU HU
Vendor Threat Intelligence
Malware configuration found for:
GuLoader NSIS
Details
GuLoader
a c2 URL, a useragent string, and a string XOR key
GuLoader
an XOR decryption key and an extracted component
NSIS
extracted archive contents
Malware family:
formbook
ID:
1
File name:
Justi pago.tar
Verdict:
Malicious activity
Analysis date:
2026-02-27 12:52:45 UTC
Tags:
arch-exec formbook xloader

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
File Type:
exe x32
Detections:
Trojan-Downloader.Win32.Minix.sb Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sba HEUR:Trojan-Downloader.Win32.Minix.gen
Gathering data
Threat name:
Win32.Trojan.Kepavll
Status:
Malicious
First seen:
2026-02-26 15:55:10 UTC
File Type:
PE (Exe)
Extracted files:
36
AV detection:
21 of 36 (58.33%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:formbook family:guloader discovery downloader rat spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Formbook payload
Formbook
Formbook family
Guloader family
Guloader,Cloudeye
Unpacked files
SH256 hash:
4a6b8d26d298279a62f2a27aa6a8a9b67db22a2195f9e4de3c19dccb0a0f8126
MD5 hash:
f46329e59f449cdcd96a1d78b4e96f59
SHA1 hash:
007386fadca47afbe5632420c46f658a978eb688
SH256 hash:
23d618a0293c78ce00f7c6e6dd8b8923621da7dd1f63a070163ef4c0ec3033d6
MD5 hash:
192639861e3dc2dc5c08bb8f8c7260d5
SHA1 hash:
58d30e460609e22fa0098bc27d928b689ef9af78
SH256 hash:
89a82c4849c21dfe765052681e1fad02d2d7b13c8b5075880c52423dca72a912
MD5 hash:
b7d61f3f56abf7b7ff0d4e7da3ad783d
SHA1 hash:
15ab5219c0e77fd9652bc62ff390b8e6846c8e3e
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments