🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5a4f84c60fece4f8ffdccfc11eede551f1e06d71a544c64606630dfa68a5a149. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 5a4f84c60fece4f8ffdccfc11eede551f1e06d71a544c64606630dfa68a5a149
SHA3-384 hash: 798385c17f12aadef8a77496e9f001c26b82f96356b55a69fc13194e0f5a46d6202f031a8f58f86a6ad35ee2501cf77e
SHA1 hash: 34f33b63dff4e2f80f394fd3dbfc58c1efeb9978
MD5 hash: 5641e02cdef77ea20efb4003533c74ac
humanhash: oscar-jig-juliet-quiet
File name:5a4f84c60fece4f8ffdccfc11eede551f1e06d71a544c64606630dfa68a5a149.img
Download: download sample
Signature GuLoader
File size:1'703'936 bytes
First seen:2025-11-05 06:30:40 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:b34zyneaZ5H+BljpP97TVKehyK5X65f7n9YEM9E9yuJRG6Hs9p0Ai:b3yyne0+BljpV7T1oK5X65ff179sIAi
TLSH T1377523048664B923EA52773009335B3529F9DE792D12C8A3BB2C77862F397696D4F31C
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter JAMESWT_WT
Tags:ftp-carbognin-it GuLoader img

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
agenttesla shellcode
Gathering data
Verdict:
Malicious
File Type:
iso
First seen:
2025-03-20T04:27:00Z UTC
Last seen:
2025-11-06T07:17:00Z UTC
Hits:
~1000
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-03-20 17:24:51 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments