🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9e9dd78182dc2437a7c5ff4df1acd37bafe1c2232af97912008b1ea75fa8411. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: b9e9dd78182dc2437a7c5ff4df1acd37bafe1c2232af97912008b1ea75fa8411
SHA3-384 hash: 10120e5e32d548d712872b87aef5eeea3e530a53e2546c11ab8c5c0e6fbf3f4b1e930ed283484aa9c1442272b225e839
SHA1 hash: 8a9d676cff686386b6ef82058c8fc939ea8f45e6
MD5 hash: 95f9298c61cf3fc93b39d0de7b8a40e4
humanhash: failed-montana-triple-jersey
File name:platba_předem.img.iso
Download: download sample
Signature GuLoader
File size:1'245'184 bytes
First seen:2026-05-20 18:09:28 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:hkBtT35B47dqptbMChowQoUlWEjTMlfsc+aacmmb:eJBAILXFQoSW8IFstRcJ
TLSH T1D64522451B22D8A7E8D287B1EEB943F353BB2E25F090426F370CBE697FB20554645352
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter TomU
Tags:GuLoader iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
CH CH
File Archive Information

This file archive contains 13 file(s), sorted by their relevance:

File name:indkomstaar.txt
File size:631 bytes
SHA256 hash: 5acd0b55bd90c5fd4e0349e8b1cb8a812bb826f79a4ba146b11485ed3a805114
MD5 hash: e2fdd4a3959d88154d08bb808d9c8d5d
MIME type:text/plain
Signature GuLoader
File name:etagerers.ini
File size:250 bytes
SHA256 hash: 0e6230981463cf28783f7b9eab58d26f5364e587eab6f966fd2fe2ce1b9db992
MD5 hash: 47b11e851c7062e457014aa5690760fe
MIME type:text/plain
Signature GuLoader
File name:Recirkuleringens.mot
File size:1'243'704 bytes
SHA256 hash: 3ddb019c1c5dc6f40a997e8696ce8039c73a8d3328415180ae30228eff315850
MD5 hash: de007d7c54498faa0c022f51cb6e2802
MIME type:application/octet-stream
Signature GuLoader
File name:PLATBA_P.BAT
File size:559'624 bytes
SHA256 hash: 19b2ed20a1802b7ebaf9ea0e0e2317770b95fea6d8ce92cfb142b58ab3d65c00
MD5 hash: c2f1a4e56c049221fe1fb8a28a135035
MIME type:application/x-dosexec
Signature GuLoader
File name:elefantordnernes.jpg
File size:8'462 bytes
SHA256 hash: 475265b07b3e9b1d12d0b421761bdcddb22af5c4bc0d82ec47529f0f71ccc815
MD5 hash: 46cf085532e55a23ce8e4f3f9b58e067
MIME type:image/jpeg
Signature GuLoader
File name:cytogenetiske.txt
File size:694 bytes
SHA256 hash: 5c928db2d06e28d9ecfc12b4a6b0693c6c1ee89a1dad3572fabbbac65f873f90
MD5 hash: 649293eeada87846da77418ac440598d
MIME type:text/plain
Signature GuLoader
File name:Fortager114.txt
File size:344 bytes
SHA256 hash: dcbe5cd36f4903ddc08ba392047bbf6dbc1e1c75023c8f89e9ed51362abf3cf1
MD5 hash: 0fc2c645235f3217d945269db0be5d3a
MIME type:text/plain
Signature GuLoader
File name:calvinistens.par
File size:179'205 bytes
SHA256 hash: 5757645ab576df3b4d3fa1507f70c58326fb3fbf687ba77d07fb10f6ce0de99b
MD5 hash: 7f2c07ef534a1fe46edf4202fc9ad5c8
MIME type:application/octet-stream
Signature GuLoader
File name:Lussingers.Fli
File size:323'806 bytes
SHA256 hash: a32f258c3dcf7588da253d3075f5646f61c0fb41185eda60ba21767a00623ff2
MD5 hash: 9c8b00754f14f59c609408494c970af9
MIME type:application/octet-stream
Signature GuLoader
File name:tauriform.jpg
File size:4'001 bytes
SHA256 hash: 3f1522580e6b2ae4cb6e9129bdf91f976da58af8778c8b4e20b98fc7ff8ea4e2
MD5 hash: e325e8ba551c88f6670ddd4d6c84af3b
MIME type:image/jpeg
Signature GuLoader
File name:petaline.jpg
File size:28'442 bytes
SHA256 hash: 10588fbf8eb168fdd8f278a48360324f49ba996a94a1a95d6a0d04e41f573865
MD5 hash: fdee890b6e519df61f3c9c7130b4cf93
MIME type:image/jpeg
Signature GuLoader
File name:Antiglobulin.Til
File size:68'484 bytes
SHA256 hash: 4a1d792922bf8a787d36b644fb301547df66db1f008df11e8df7431af04d1ab8
MD5 hash: ca641431c01df2e1b77a4c2a01eb7091
MIME type:text/plain
Signature GuLoader
File name:vain.ini
File size:476 bytes
SHA256 hash: d07741e9d6d6e279d241c83bcf12b39a25900ad184e0702ad7a255eca1ca1f76
MD5 hash: 058b63aad7defc156da49d5b9d56a3ec
MIME type:text/plain
Signature GuLoader
Vendor Threat Intelligence
Malware configuration found for:
Archives GuLoader NSIS
Details
Archives
extracted archive contents
GuLoader
an XOR decryption key and an extracted component
NSIS
extracted archive contents
Verdict:
Malicious
File Type:
iso
First seen:
2025-02-26T07:23:00Z UTC
Last seen:
2026-05-22T17:02:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-03-05 07:13:00 UTC
File Type:
Binary (Archive)
Extracted files:
13
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_detect_tls_callbacks
Rule name:pe_no_import_table
Description:Detect pe file that no import table
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso b9e9dd78182dc2437a7c5ff4df1acd37bafe1c2232af97912008b1ea75fa8411

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments