🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85db041a1f97138aae96105d11a720a6bfcc1a638e9179682b2ca9cae5cc5c9c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: 85db041a1f97138aae96105d11a720a6bfcc1a638e9179682b2ca9cae5cc5c9c
SHA3-384 hash: f602ed7c19740e87855108881f78715ec00183d5218c96d2588152555edef9bc58db975cb9e09faa8b8edcb065b6d0be
SHA1 hash: cb47eeac1038dd0d2994afccb31efac4a96cd567
MD5 hash: 918364326dc9b1865476e4305c7cba77
humanhash: fruit-finch-alpha-mississippi
File name:177XHEHEN31592AXBLRiderX_20250519102019.7z
Download: download sample
Signature GuLoader
File size:438'853 bytes
First seen:2026-05-20 17:54:29 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:YLIe4fYX0QWKQaVWBt/wZd7bOqVpm27Ddg9e:zYkQ130t/wZ5CqVk2Vgk
TLSH T17D9423B09F0655DDF289EA93543F03226B1DF5217E5DC87BAB8E8828065FD71078B708
Magika zip
Reporter TomU
Tags:GuLoader zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:177XHEHEN31592A(BLRider)_20250519102019.exe
File size:535'725 bytes
SHA256 hash: 3bb103bfa52137624c0932b092360c74b5094502a1dbb7b1ea4553fe898b22f7
MD5 hash: 0b90c86d6d1c4807f8189564dab35d2e
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
injection uloader virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug evasive installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance
Verdict:
Malicious
File Type:
zip
First seen:
2025-07-24T12:20:00Z UTC
Last seen:
2026-05-13T08:17:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Etset
Status:
Malicious
First seen:
2025-07-24 18:50:42 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
25 of 38 (65.79%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip 85db041a1f97138aae96105d11a720a6bfcc1a638e9179682b2ca9cae5cc5c9c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments