🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c44510db966154804a6ca2f3f2c62dd6f42eb01650cd555aff35668f8b591392. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: c44510db966154804a6ca2f3f2c62dd6f42eb01650cd555aff35668f8b591392
SHA3-384 hash: 6ac6eba8b4e7925ae1bb654860f4f4d63ed1d4cfd28f3b034cd040e00dcb2858b81181be7f2855f7f56f5a4a769dc80a
SHA1 hash: ffddf2c4b277b3a6bfd2106757d367215c16d016
MD5 hash: 2280d7e3f4b3a618108b2d097f57f95b
humanhash: jersey-red-video-kentucky
File name:Quote-SA70451153766809567875351061-24_pdf.txz
Download: download sample
Signature GuLoader
File size:603'476 bytes
First seen:2025-02-28 13:08:28 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:NK1rtf6dop4Co3k3I4kkmCW0gHJAXnr23e4MHnrsLF8+F4z:A1rwoZ8sIXfC4HROLHru4z
TLSH T1CAD4339FE6EC8E0161214AB81BA8DE7497009D9E04D6BF53DA146698FF85FCE6CCF500
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter nfsec_pl
Tags:exe GuLoader pdf rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
721
Origin country :
PL PL
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Quote-SA70451153766809567875351061-24_pdf.exe
File size:829'406 bytes
SHA256 hash: bc3f66f7dbab0b0e60bb989d1e53f8afd00a9b88b370c12c364cf450eb61856e
MD5 hash: 51493da79f7be2add42abc448ce8ffd1
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context blackhole guloader installer masquerade microsoft_visual_cc obfuscated overlay packed packer_detected
Threat name:
Win32.Trojan.ZmutzyPong
Status:
Malicious
First seen:
2025-02-28 13:09:20 UTC
File Type:
Binary (Archive)
Extracted files:
19
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:darkcloud family:guloader discovery downloader spyware stealer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Legitimate hosting services abused for malware hosting/C2
Loads dropped DLL
Reads user/profile data of local email clients
Reads user/profile data of web browsers
DarkCloud
Darkcloud family
Guloader family
Guloader,Cloudeye
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar c44510db966154804a6ca2f3f2c62dd6f42eb01650cd555aff35668f8b591392

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments