🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b595b68250afbadddf987693c116beb8a3e832b1980782bc5e28ac4c485fe940. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 15


Intelligence 15 IOCs YARA 3 File information Comments

SHA256 hash: b595b68250afbadddf987693c116beb8a3e832b1980782bc5e28ac4c485fe940
SHA3-384 hash: 62845ff1a7c7e82ce557d26095401e93267b0b22f739419f65a169a67568afa571f96bd50cdea479267f72ecc48c2448
SHA1 hash: 0f0d0f31a9a19304883da5c3ed502b9894506bdb
MD5 hash: de45ac1412091d09d46430db133a905f
humanhash: mirror-kitten-jersey-cola
File name:inquiry_29202500000000.pdf.exe
Download: download sample
Signature GuLoader
File size:957'424 bytes
First seen:2026-05-20 17:06:44 UTC
Last seen:2026-05-20 18:08:09 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 24576:daSN9/uarj4tlWqVeFhyDD8QlE9uAchcaIdb+p0H1yCvL:nN9/stlW1+gQe7aIdKp0HV
TLSH T1171522443398DE7BF9224EB4C039D3F50964CD09A9D15203476E7C9BBDB2261BAF92C6
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon 34fcf0d4dcf0d2cc (9 x GuLoader, 4 x MassLogger, 4 x VIPKeylogger)
Reporter TomU
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Indsamlings
Issuer:Indsamlings
Algorithm:sha256WithRSAEncryption
Valid from:2025-09-11T02:34:59Z
Valid to:2026-09-11T02:34:59Z
Serial number: 6717b42ca6b4268b07ebf98f025f53b53a15f89f
Thumbprint Algorithm:SHA256
Thumbprint: 146b646a331e3d9048267a0e915cd163e8033603cfb658dfe29d0bbc0b3c78a5
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
102
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
GuLoader NSIS
Details
GuLoader
an XOR decryption key and an extracted component
GuLoader
a c2 URL, a useragent string, and a string XOR key
NSIS
extracted archive contents
Malware family:
formbook
ID:
1
File name:
inquiry_29202500000000.pdf.exe
Verdict:
Malicious activity
Analysis date:
2026-05-20 17:12:36 UTC
Tags:
formbook xloader stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
underscore injection obfusc virus
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Launching a service
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug installer installer installer-heuristic masquerade microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-11-02T20:00:00Z UTC
Last seen:
2026-05-22T09:45:00Z UTC
Hits:
~100
Detections:
Packed.NSIS.Krynis.sb HEUR:Trojan.Win32.GuLoader.gen VHO:Trojan.NSIS.GuLoader.gen PDM:Trojan.Win32.Badex.d Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sba
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-11-03 13:03:37 UTC
File Type:
PE (Exe)
Extracted files:
46
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
cloudeye
Similar samples:
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Loads dropped DLL
Unpacked files
SH256 hash:
b595b68250afbadddf987693c116beb8a3e832b1980782bc5e28ac4c485fe940
MD5 hash:
de45ac1412091d09d46430db133a905f
SHA1 hash:
0f0d0f31a9a19304883da5c3ed502b9894506bdb
SH256 hash:
1e40211af65923c2f4fd02ce021458a7745d28e2f383835e3015e96575632172
MD5 hash:
466179e1c8ee8a1ff5e4427dbb6c4a01
SHA1 hash:
eb607467009074278e4bd50c7eab400e95ae48f7
SH256 hash:
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
MD5 hash:
0d7ad4f45dc6f5aa87f606d0331c6901
SHA1 hash:
48df0911f0484cbe2a8cdd5362140b63c41ee457
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe b595b68250afbadddf987693c116beb8a3e832b1980782bc5e28ac4c485fe940

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments