🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aac899cfe7e5ed2761250c4eb9f89c873087d6145bca278e88bb0ca0d36aa4eb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 14


Intelligence 14 IOCs YARA 1 File information Comments

SHA256 hash: aac899cfe7e5ed2761250c4eb9f89c873087d6145bca278e88bb0ca0d36aa4eb
SHA3-384 hash: 3ecb0a39d887c4b3b947a6b3efa0a81dc3d7efeaf23a8ba56282f687459b8d8ebb20b90184db9d27192e80d62b03adb1
SHA1 hash: b708bae1d2e3ac571005a359cc50d7cd23862c18
MD5 hash: 7bdb9c35cae12a453ca9fa3f3aaff332
humanhash: yankee-helium-fourteen-jersey
File name:aac899cfe7e5ed2761250c4eb9f89c873087d6145bca278e88bb0ca0d36aa4eb
Download: download sample
Signature GuLoader
File size:578'736 bytes
First seen:2025-10-09 14:23:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 7eae418c7423834ffc3d79b4300bd6fb (66 x GuLoader, 23 x RemcosRAT, 21 x AgentTesla)
ssdeep 12288:5gAr+mcascFoTz8HVhvkVPeY20iCujzPmLb0XiyW6/9f+:5gArkAoTz889t9IIY/9f+
Threatray 1'898 similar samples on MalwareBazaar
TLSH T10EC423F1A360CA97D97698310EFA97671BB98A1026ED9F039F507D1F3E02751C62E321
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon c4dadadad2f492c2 (148 x GuLoader, 51 x RemcosRAT, 23 x VIPKeylogger)
Reporter adrian__luca
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
75
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
22092025_0258_Scan_022209_pdf.bat.zip
Verdict:
Malicious activity
Analysis date:
2025-10-09 14:38:40 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
94.9%
Tags:
injection virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Creating a file
Creating a file in the %temp% subdirectories
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Searching for the window
Delayed reading of the file
Sending a custom TCP request
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
guloader installer microsoft_visual_cc obfuscated overlay packed packer_detected
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-09-21T14:00:00Z UTC
Last seen:
2025-10-09T08:56:00Z UTC
Hits:
~10000
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-09-21 16:52:12 UTC
File Type:
PE (Exe)
Extracted files:
16
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Legitimate hosting services abused for malware hosting/C2
Loads dropped DLL
Verdict:
Suspicious
Tags:
n/a
YARA:
n/a
Unpacked files
SH256 hash:
aac899cfe7e5ed2761250c4eb9f89c873087d6145bca278e88bb0ca0d36aa4eb
MD5 hash:
7bdb9c35cae12a453ca9fa3f3aaff332
SHA1 hash:
b708bae1d2e3ac571005a359cc50d7cd23862c18
SH256 hash:
502ad6a7c0d5c61f7d34c485f60c94e5511ee44da70564283b26957b07e1607c
MD5 hash:
ef6fcc46fbb38fc098a6885d4e31cac1
SHA1 hash:
2994e337feb97d8ac652f42f7a4f3543bb62f4fa
SH256 hash:
3bfc5b7dababe8750f85b54e1672cc324c50e85dd823ada5041b57192d721610
MD5 hash:
4461c76c548e0045ab9956ee3a0db139
SHA1 hash:
d41b72b268f89d6ef8896ce653b3d6c526d0b623
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments