🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e95dde9ae59b93ed29b2a614a781f5582d5fe7c43dd8bf09aab41c4bc4cee92. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 14


Intelligence 14 IOCs YARA 2 File information Comments

SHA256 hash: 6e95dde9ae59b93ed29b2a614a781f5582d5fe7c43dd8bf09aab41c4bc4cee92
SHA3-384 hash: 68d26654448b0c18b4e174f5979dd92365eab8e3ef074a0cd51dda5c0418df42c0f15c0e17f285f7b285e6f2f70db836
SHA1 hash: af3a2c5b20e1f2bd6db115046bc477dcd49847bf
MD5 hash: 946be1c17d3dc871fc36b4ac46ca8d9d
humanhash: salami-lion-december-east
File name:Autopsychosis.exe
Download: download sample
Signature GuLoader
File size:832'904 bytes
First seen:2025-11-20 16:24:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 3abe302b6d9a1256e6a915429af4ffd2 (299 x GuLoader, 39 x Formbook, 25 x Loki)
ssdeep 12288:ZErJA5UmfOB5IRJnjkoiMElsm5LghowLEm6MZ5Cr1Szu1VuFSSJfSuQUXUaX9hG5:f53f45KZkohTo8iE5/CXSpJfSuQm77G5
Threatray 3'308 similar samples on MalwareBazaar
TLSH T19F05F09257959973C4633EB8C393DF35B6665F4C7A238D0212E2BDA3FBF4942AD001A1
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 30e443c4fc3050d9 (5 x GuLoader)
Reporter James_inthe_box
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Narcolepsy
Issuer:Narcolepsy
Algorithm:sha256WithRSAEncryption
Valid from:2025-11-20T05:48:15Z
Valid to:2026-11-20T05:48:15Z
Serial number: 64e7d7f4708f980772d59c5b8c0d576583b70dc7
Thumbprint Algorithm:SHA256
Thumbprint: db664fe7b2d9efb83e1123321b86d88a8401d0d989e237c2661979e44c9f916a
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
148
Origin country :
US US
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
Autopsychosis.exe
Verdict:
Malicious activity
Analysis date:
2025-11-20 16:26:14 UTC
Tags:
stealer ultravnc rmm-tool auto-reg evasion telegram exfiltration agenttesla ims-api generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
90.2%
Tags:
injection virus blic
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Delayed reading of the file
Creating a file in the %AppData% subdirectories
Creating a file in the %temp% subdirectories
Searching for synchronization primitives
Launching the default Windows debugger (dwwin.exe)
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis overlay signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-11-20T11:17:00Z UTC
Last seen:
2025-11-22T14:10:00Z UTC
Hits:
~100
Detections:
Trojan.NSIS.Makoob.sbe Trojan.NSIS.Makoob.sbd Trojan.NSIS.Makoob.sbb Trojan.NSIS.Makoob.sba HEUR:Trojan.Win32.Makoob.gen Trojan-Downloader.Win32.Minix.sb Trojan.Win32.Guloader.sb
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-11-20 14:46:07 UTC
File Type:
PE (Exe)
Extracted files:
42
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
agenttesla
Score:
  10/10
Tags:
family:agenttesla discovery installer keylogger persistence spyware stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious behavior: SetClipboardViewer
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
NSIS installer
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Executes dropped EXE
Loads dropped DLL
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
AgentTesla
Agenttesla family
Malware Config
C2 Extraction:
https://api.telegram.org/bot6619004667:AAHS_19GZLZR2AsuEv22p3V3SQQHEGnjlJY/
Verdict:
Suspicious
Tags:
loader guloader
YARA:
NSIS_GuLoader_July_2024
Unpacked files
SH256 hash:
6e95dde9ae59b93ed29b2a614a781f5582d5fe7c43dd8bf09aab41c4bc4cee92
MD5 hash:
946be1c17d3dc871fc36b4ac46ca8d9d
SHA1 hash:
af3a2c5b20e1f2bd6db115046bc477dcd49847bf
SH256 hash:
98160b4ebb4870f64b13a45f5384b693614ae5ca1b5243edf461ca0b5a6d479a
MD5 hash:
de3558ce305e32f742ff25b697407fec
SHA1 hash:
d55c50c546001421647f2e91780c324dbb8d6ebb
SH256 hash:
a1390a78533c47e55cc364e97af431117126d04a7faed49390210ea3e89dd0e1
MD5 hash:
fbe295e5a1acfbd0a6271898f885fe6a
SHA1 hash:
d6d205922e61635472efb13c2bb92c9ac6cb96da
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments