🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa5e0022e103514e0d90c7528e6aca4e6cd03ca346087ca9aee832a9ee141588. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 13


Intelligence 13 IOCs YARA 1 File information Comments

SHA256 hash: aa5e0022e103514e0d90c7528e6aca4e6cd03ca346087ca9aee832a9ee141588
SHA3-384 hash: b7b46fdc476d80977637beff9bda6366269d6be567cbc3f7ab103043d136196071cf2448178cd9e4968574b1131749d2
SHA1 hash: 6c17fe30e2cb59e17ca46d07bebf79b3019683a1
MD5 hash: 524c12713c26ce152f9ce0413ef733e0
humanhash: comet-item-red-robert
File name:aa5e0022e103514e0d90c7528e6aca4e6cd03ca346087ca9aee832a9ee141588
Download: download sample
Signature GuLoader
File size:684'084 bytes
First seen:2025-12-08 15:46:47 UTC
Last seen:2026-01-09 15:06:27 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ced282d9b261d1462772017fe2f6972b (129 x Formbook, 124 x GuLoader, 72 x RemcosRAT)
ssdeep 12288:qQakJ6mO9poMq2iANKQAFdMWUbHI5j5NlubChtXX1n:xfJ6mO9Dq5QAFKWUMbobCXR
TLSH T1ABE423C512D18AF7C66203BDE46A6BD04BEDA8B51141070393E06FFDB926F4B8B5D522
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon dcd4c4c0c8c4e478 (1 x GuLoader)
Reporter adrian__luca
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
89
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
aa5e0022e103514e0d90c7528e6aca4e6cd03ca346087ca9aee832a9ee141588.exe
Verdict:
Malicious activity
Analysis date:
2025-12-08 15:50:45 UTC
Tags:
darkcloud upx ims-api generic

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.1%
Tags:
virus nsis blic sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Delayed reading of the file
Creating a file in the Windows subdirectories
Creating a file in the %temp% subdirectories
Sending a custom TCP request
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-11-25T03:26:00Z UTC
Last seen:
2025-12-10T03:37:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan.Win32.Guloader.gen Trojan-Downloader.Win32.Minix.sb Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sbd Trojan.NSIS.Makoob.sba Packed.NSIS.Krynis.sb
Gathering data
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Guloader
Status:
Suspicious
First seen:
2025-11-25 06:27:25 UTC
File Type:
PE (Exe)
Extracted files:
36
AV detection:
20 of 36 (55.56%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:darkcloud family:guloader discovery downloader installer stealer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Loads dropped DLL
DarkCloud
Darkcloud family
Guloader family
Guloader,Cloudeye
Malware Config
C2 Extraction:
https://api.telegram.org/bot8241403803:AAFl1Naxqm1AhH6mIvXtgEqCGQH7BD1-UnI/sendMessage?chat_id=8263342306
Verdict:
Suspicious
Tags:
loader guloader
YARA:
NSIS_GuLoader_July_2024
Unpacked files
SH256 hash:
aa5e0022e103514e0d90c7528e6aca4e6cd03ca346087ca9aee832a9ee141588
MD5 hash:
524c12713c26ce152f9ce0413ef733e0
SHA1 hash:
6c17fe30e2cb59e17ca46d07bebf79b3019683a1
SH256 hash:
269d232712c86983336badb40b9e55e80052d8389ed095ebf9214964d43b6bb1
MD5 hash:
34442e1e0c2870341df55e1b7b3cccdc
SHA1 hash:
99b2fa21aead4b6ccd8ff2f6d3d3453a51d9c70c
SH256 hash:
e664756ea6bfb01787ee6dfe299f1e1cc52b0453759771124c9359cb3cf79cb4
MD5 hash:
602d953c391a05d2be162a661962c598
SHA1 hash:
794b83002517dca3a017337946d39df55646e3e0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments