MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a073704e18e10cd3e8d20e61b0671292d2a7ef52e4cd8e2b1c88a7ff62c3bf73. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 15


Intelligence 15 IOCs YARA 3 File information Comments

SHA256 hash: a073704e18e10cd3e8d20e61b0671292d2a7ef52e4cd8e2b1c88a7ff62c3bf73
SHA3-384 hash: 989e9d1443725b19941713d976466b1a4a5b727ff115c2990689d8b08d45dec2dbc1094169f3fdfbafb7746ff9ce218c
SHA1 hash: df87540b6af75f79909d9ebfc739e929bfbc5ed0
MD5 hash: ae5f2f7ace440ca63a6f5e177ff93b68
humanhash: snake-alanine-fillet-october
File name:a073704e18e10cd3e8d20e61b0671292d2a7ef52e4cd8e2b1c88a7ff62c3bf73
Download: download sample
Signature GuLoader
File size:334'056 bytes
First seen:2026-06-08 09:49:42 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash ced282d9b261d1462772017fe2f6972b (127 x Formbook, 123 x GuLoader, 72 x RemcosRAT)
ssdeep 6144:K9X0G7HCo89joe9fL6HrXUcxKterwHy9MtTHiytdjbWYaSFs/ktC:80IHCoK0epLorXrmekSORfne
TLSH T1B7641212B290C467CE971570487EC7B6C6F182F8432D6F676B14376A3872AD34B1EE28
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon c4dadadad2f492c2 (148 x GuLoader, 51 x RemcosRAT, 23 x VIPKeylogger)
Reporter adrian__luca
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Brittlewort
Issuer:Brittlewort
Algorithm:sha256WithRSAEncryption
Valid from:2026-04-14T08:28:58Z
Valid to:2027-04-14T08:28:58Z
Serial number: 2ea59a85399995ac2301a881abdb3c9ede9cf2bc
Thumbprint Algorithm:SHA256
Thumbprint: b8359c0e1704973aaa6e6c76d59ab2b12abd69391dcf8c693a535641372a2b98
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
agenttesla
ID:
1
File name:
321.EXE
Verdict:
Malicious activity
Analysis date:
2026-05-18 08:21:03 UTC
Tags:
stealer ultravnc rmm-tool ftp agenttesla exfiltration amsi-bypass

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
injection obfusc virus nsis
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Creating a file in the %temp% directory
Delayed reading of the file
Deleting a recently created file
Unauthorized injection to a recently created process
Restart of the analyzed sample
Connection attempt to an infection source
Sending an HTTP GET request to an infection source
Sending an HTTP GET request
DNS request
Connection attempt
Query of malicious DNS domain
Sending a TCP request to an infection source
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug guloader installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-18T05:11:00Z UTC
Last seen:
2026-06-08T03:59:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.Minix
Status:
Malicious
First seen:
2026-05-18 07:51:47 UTC
File Type:
PE (Exe)
Extracted files:
9
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cloudeye
Similar samples:
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery installer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Loads dropped DLL
Unpacked files
SH256 hash:
a073704e18e10cd3e8d20e61b0671292d2a7ef52e4cd8e2b1c88a7ff62c3bf73
MD5 hash:
ae5f2f7ace440ca63a6f5e177ff93b68
SHA1 hash:
df87540b6af75f79909d9ebfc739e929bfbc5ed0
SH256 hash:
d09a8b3ade4ba4b7292c0b3da1bcb4b6c6e2012e0ccfd5e029a54af73a9e1b57
MD5 hash:
4ca4fd3fbefa2f6e87e6e9ee87d1c0b3
SHA1 hash:
7cdbeb5ff2b14b86af04e075d0ca651183ea5df4
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments