🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb460d90e9c620728ef281c2986762fb43bf84ef6568e17fd38dffaec88fe510. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: bb460d90e9c620728ef281c2986762fb43bf84ef6568e17fd38dffaec88fe510
SHA3-384 hash: 2a98b31caace8d1cbd81b71d016117dd267a158fd8a2ba0a1b4fc12d09c1ce44260a2d58397bf7f104a2f0ff6703d878
SHA1 hash: 7010a40cca5210a1272af7fb6002531d8704e6ce
MD5 hash: 2d36444e61ccd6677e8600c5970a30c5
humanhash: butter-happy-alpha-rugby
File name:PO#940834894039430849484803408.PDF.rar
Download: download sample
Signature GuLoader
File size:766'181 bytes
First seen:2026-05-21 13:50:32 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:YLq7KinsooY3K5PDCCt/OcEdbc8+t5z5sCu6N/lGtPtnIR8hZAh+kXeznCBoUjbd:SyKgogk+WOrdbB+t5z5Z/kXhZ3kX+vEp
TLSH T1F5F43310A7A73F54DFECEF19C6D0A475EC2633AD9BD66101D8B6D9F36E80A42A300935
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
CH CH
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:fondlings.Und
File size:327'887 bytes
SHA256 hash: a9ff39e23b50cacfb652f3c6dac52b066adb59adbc71a69a7f6361fd6ddf4ecf
MD5 hash: 5cdd6dd7033d441471db5e8a43e5f923
MIME type:application/octet-stream
Signature GuLoader
File name:Ornitologisk.Aft
File size:54'663 bytes
SHA256 hash: 40426fee8802d21e821cdb9380dc50750f8e3015d9c486e11685b06e19a8c59b
MD5 hash: 67b3616cc286b91c6bd34e0ef06458c5
MIME type:text/plain
Signature GuLoader
File name:sejrvinding.ten
File size:467'817 bytes
SHA256 hash: d68752bf5834410ad6d6490a1161f0f28049e2f3caa008f21517b029cb37dd97
MD5 hash: 1c8433504309e2e0f963307867105afa
MIME type:application/octet-stream
Signature GuLoader
File name:Samfundsforsknings.kom
File size:256'686 bytes
SHA256 hash: e2d13df2a397c7e02162dbcf1ef3859bee27b1621366668c3fd2624c73983da5
MD5 hash: 3f193071e013baaba98787e052095e44
MIME type:application/octet-stream
Signature GuLoader
File name:diskrimineredes.lge
File size:471'572 bytes
SHA256 hash: 71c4ec4f1e49ee16b34837595a849d1105a673971ff6c896f70cc616476a066e
MD5 hash: 9bc28d4cd4ff5fce5b787f203e07cb2e
MIME type:application/octet-stream
Signature GuLoader
File name:Rendets.spa
File size:404'271 bytes
SHA256 hash: 44510d340bbc5f63ca2c8f10b633eb4b9f3161ba993ec6eedd188a91e0ea29cb
MD5 hash: f49b14a84935d3315799294d72c27588
MIME type:application/octet-stream
Signature GuLoader
File name:PO#940834894039430849484803408.PDF.com
File size:796'468 bytes
SHA256 hash: 761dffc1e47769b81f33e40f159cb36a54d7d241f278f49e8383e0a28e55dbab
MD5 hash: b8914185bfef219cccd80034dc55ffbd
MIME type:application/x-dosexec
Signature GuLoader
File name:kopierende.six
File size:422'201 bytes
SHA256 hash: ed8f9d192fead1a74a737302a23093ed0aa41683db04a4f1d5ad6ae495bb3878
MD5 hash: ebe5427bd07c76b0b91cb5b0142b4620
MIME type:application/octet-stream
Signature GuLoader
File name:stillingsgruppernes.txt
File size:358 bytes
SHA256 hash: 2d53502542c7fcdf0895f8d47bd7e3d7155110373286faf6a25798b5b6547548
MD5 hash: 9da94026648c2042e0f6de8c1c01a5d0
MIME type:text/plain
Signature GuLoader
File name:Tingsted.toe
File size:335'763 bytes
SHA256 hash: 164c9c64abf8ff20948865d0813887c14e0869a0d157618dcdc39d771c68409e
MD5 hash: 81f48e5bba988b09927c5978d2f503dc
MIME type:application/octet-stream
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
obfuscate shell virus nsis
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm encrypted evasive evasive fingerprint installer installer installer-heuristic masquerade microsoft_visual_cc nsis phishing reconnaissance smb
Verdict:
Malicious
File Type:
rar
First seen:
2024-11-08T04:08:00Z UTC
Last seen:
2026-04-20T18:03:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2024-11-08 11:21:23 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:guloader discovery downloader execution persistence ransomware
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Family: Guloader,Cloudeye
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar bb460d90e9c620728ef281c2986762fb43bf84ef6568e17fd38dffaec88fe510

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments