🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8eae0991f6147c8b5755d19a6093627363fd459b8bbec352a14ef7ab463ea9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: b8eae0991f6147c8b5755d19a6093627363fd459b8bbec352a14ef7ab463ea9a
SHA3-384 hash: 8673f4c995b59e46fb7489f863e66012656d5cdcfca995931adc43149fb6417cc50906b6f17475df8ed165d990f928b6
SHA1 hash: beec65e7fa05e5d5233ceb39b5f4b0b12eed498c
MD5 hash: 04485f14c468c9a61c3aabd55bdab899
humanhash: ten-edward-hot-aspen
File name:doc20240715-00034.img
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2026-05-21 14:39:46 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:DpkXGhIfigEMBI8Eh9xDLgQWoQt1l5Ep9T6LHeL61qckSczRZjhFj6ApzF9EqRfn:e9KgEMUDLgBpipBMHeO8FS4pu448
TLSH T12745015173D0D071D2A80FB76CE2E96A4A65FD277E018F17368CBB693B3E54D4928321
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter TomU
Tags:GuLoader img

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
CH CH
File Archive Information

This file archive contains 13 file(s), sorted by their relevance:

File name:Incomer47.uds
File size:8'845 bytes
SHA256 hash: 467e7d6f30912c31789d05bb06abd9a16c29fb335d30b976c0dd88136e015227
MD5 hash: 755a1e8989b34127d0e2949c292f0da4
MIME type:application/octet-stream
Signature GuLoader
File name:Faglrtes161.tru
File size:7'563 bytes
SHA256 hash: 4b3cdc417b8e908c6dabef03fa9bdc0ab0b25e88a01254395378cb0797892f4e
MD5 hash: bac1bae5e7c710632073fe5e30d7ea95
MIME type:application/octet-stream
Signature GuLoader
File name:Isthmoid128.txt
File size:366 bytes
SHA256 hash: 841bab0a6fab43107267768ff6245474edab478ccf66b2d4da8a4101cc397d8f
MD5 hash: 4c854e2e4b6eb1491f9db937706c750c
MIME type:text/plain
Signature GuLoader
File name:Appellanterne.Voc
File size:198'141 bytes
SHA256 hash: 28efb23d938a4c171e8d715c9b6dd22976b791f9d886b6e9d149d662f9ed5e86
MD5 hash: a5d6678d11fab6f8524d230cb3e48a50
MIME type:application/octet-stream
Signature GuLoader
File name:System.dll
File size:11'776 bytes
SHA256 hash: 2e226715419a5882e2e14278940ee8ef0aa648a3ef7af5b3dc252674111962bc
MD5 hash: a4dd044bcd94e9b3370ccf095b31f896
MIME type:application/x-dosexec
Signature GuLoader
File name:Cadetcy.bin
File size:2'122 bytes
SHA256 hash: cc4f4bdbe998b696ec6af8dd9d5d51abcd67674648ae24f1c59c40c431bc6e5d
MD5 hash: 45f1f0b16a621607f077ea293eff2aea
MIME type:application/octet-stream
Signature GuLoader
File name:tyrolsk.kon
File size:8'910 bytes
SHA256 hash: 8f2ae756c32aeb3cbb8274c9b27700df7f4396876a5e456b5d70583f9a019df0
MD5 hash: 4b70734414246faf83baa2bc4118b38c
MIME type:application/octet-stream
Signature GuLoader
File name:images.jpg
File size:8'211 bytes
SHA256 hash: 86fa8569a16f13965b41467fce92f0c405121758e44d38057ccdff02cc902619
MD5 hash: 189c585d59d1b5a7fc2fa0cc04777c14
MIME type:image/jpeg
Signature GuLoader
File name:DOC20240.BAT
File size:507'676 bytes
SHA256 hash: 62d92a3b2c0ee7f125f15a606659b4675a85e4053c5d82221caed28a49635b2e
MD5 hash: 4d80294b3e66e7c45202fab188cdf894
MIME type:application/x-dosexec
Signature GuLoader
File name:Poacher.lej
File size:215'185 bytes
SHA256 hash: 121e81f02d26cfd5420db6f231672a58d17ed2665a045b1400d9934d0a497b75
MD5 hash: 9a0b3392835ddde124c75008e2de0eb0
MIME type:application/octet-stream
Signature GuLoader
File name:nsDialogs.dll
File size:9'728 bytes
SHA256 hash: 067c77d51df034b4a614f83803140fbf4cd2f8684b88ea8c8acdf163edad085a
MD5 hash: 0d45588070cf728359055f776af16ec4
MIME type:application/x-dosexec
Signature GuLoader
File name:BgImage.dll
File size:7'680 bytes
SHA256 hash: 8eb85584031b2e1d74daf372e60a72f767e8861db9d4ca2dc1981511f620e51e
MD5 hash: 744f9c42403e9aabde8fc65d40bccd3e
MIME type:application/x-dosexec
Signature GuLoader
File name:shammashim.var
File size:6'005 bytes
SHA256 hash: c21232eccaca0633b46f19ddf9a0fd88f769755855cef47987e011b372e0df0d
MD5 hash: be45431798a2467546899124e4850bf5
MIME type:application/octet-stream
Signature GuLoader
Vendor Threat Intelligence
Malware configuration found for:
Archives GuLoader NSIS
Details
Archives
extracted archive contents
GuLoader
an XOR decryption key and an extracted component
GuLoader
a c2 URL, a useragent string, and a string XOR key
NSIS
extracted archive contents
Verdict:
Malicious
File Type:
iso
First seen:
2024-07-15T04:48:00Z UTC
Last seen:
2026-05-22T14:26:00Z UTC
Hits:
~1000
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2024-07-15 12:04:09 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
17 of 35 (48.57%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NSIS_April_2024
Author:NDA0N
Description:Detects NSIS installers

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

img b8eae0991f6147c8b5755d19a6093627363fd459b8bbec352a14ef7ab463ea9a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments