🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f96993469bf11269b2f0964bfb242ef71fbf224b8fd86ba1950a921735063aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 4 File information Comments

SHA256 hash: 9f96993469bf11269b2f0964bfb242ef71fbf224b8fd86ba1950a921735063aa
SHA3-384 hash: a639a317b819f8bd60acf4af0a31135f26cc9b8eec437e2cc2c1fc4a97dfb52a04ac2d72c09250aa684b633c93202e45
SHA1 hash: c48eaaab90f4254242b84c836b06467bd7b44384
MD5 hash: 236b3b67f76258071196766032128bba
humanhash: finch-lima-charlie-comet
File name:nOctubre_2025_N.z
Download: download sample
Signature GuLoader
File size:386'687 bytes
First seen:2025-10-31 16:30:08 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 6144:ysMlxFZ5vqOdSfUQIFHebM7k43b8c2/rsCzqgUkHLeU+RDlUckcf4jdiu29Fdt+s:ysIh5vqkF2Mw43jUxzqgUgLelUckOHuW
TLSH T14E8422062C06308BE556CC316777EBAC1E69BC03EA664539BED1FB0B35F64A6D1120B4
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter FXOLabs
Tags:file-pumped GuLoader z

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
BR BR
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Octubre_2025_Nómina_y_Actualización_de_Personal.pdf.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:135'266'304 bytes
SHA256 hash: b5e2a5c633d039881b702a0a9268b8b43b1c93d37d1b6284ce519f4d34e3a46c
MD5 hash: a43dd1824e0cd53a2ea35e70fbc0a058
De-pumped file size:71'168 bytes (Vs. original size of 135'266'304 bytes)
De-pumped SHA256 hash: 8e6410c0226a26f4cad573655f9a2baf0460446308a24dd7be10447c421cfcf8
De-pumped MD5 hash: 3cd0442bd07d4992642f24edce9a9543
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
underscore extens virus
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis smb
Verdict:
Malicious
File Type:
rar
First seen:
2025-10-31T14:03:00Z UTC
Last seen:
2025-11-01T02:40:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Znyonm
Status:
Malicious
First seen:
2025-10-31 16:16:24 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:SUSP_RAR_with_PDF_Script_Obfuscation
Author:Florian Roth (Nextron Systems)
Description:Detects RAR file with suspicious .pdf extension prefix to trick users
Reference:Internal Research
Rule name:SUSP_RAR_with_PDF_Script_Obfuscation_RID34A4
Author:Florian Roth
Description:Detects RAR file with suspicious .pdf extension prefix to trick users
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

z 9f96993469bf11269b2f0964bfb242ef71fbf224b8fd86ba1950a921735063aa

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments