🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c95d5e38ffd0408eb4084b35c86791791380184963b7ee89719e8754bbb68358. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: c95d5e38ffd0408eb4084b35c86791791380184963b7ee89719e8754bbb68358
SHA3-384 hash: c816e99e2fb60f1350e19f4c63f506c7b24b5aa72afcf411e884613872e1ddf4a396bd3762175885c8bc91a9098d62e8
SHA1 hash: 1341fd4d966f94693b455b1c4ac03ca3229fd80f
MD5 hash: 14f8da326798f7706a4a513f7ac141f7
humanhash: beer-maryland-kilo-vegan
File name:Bank Details.7z
Download: download sample
Signature GuLoader
File size:1'194'077 bytes
First seen:2025-09-30 01:30:38 UTC
Last seen:2025-09-30 01:34:49 UTC
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 24576:x2M1h31eUZMPEJrykHDvBYUMr3DWPxsNucjlAq3A1+QUwM:oEh1eUZMifTBY/siNJ/A1IwM
TLSH T1B745338E29E5D81D85DA1B38CB493803B6A56BE9169DD93F1DA2410CD7ECC0CDA74CCE
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter JAMESWT_WT
Tags:46-250-253-70 7z GuLoader Spam-ITA

Intelligence


File Origin
# of uploads :
2
# of downloads :
92
Origin country :
IT IT
File Archive Information

This file archive contains 19 file(s), sorted by their relevance:

File name:Valmuefrs.Ove
File size:338'227 bytes
SHA256 hash: 40922d22d898976854c6b06595354607c3fcef19324f5694555217aaf47c3b2d
MD5 hash: 0f305480d4ab1eff012352dc75256f6f
MIME type:application/octet-stream
Signature GuLoader
File name:vardapet.jpg
File size:4'351 bytes
SHA256 hash: dc7d077c02a2b19f0b3d2bed63372810c4ac84e7d4d336fa977810af9efa6e03
MD5 hash: 00ab47779e4f77bf4c0c39c953b1d848
MIME type:image/jpeg
Signature GuLoader
File name:feldspar.txt
File size:674 bytes
SHA256 hash: 0deda80958d492b34e95f8a6c84a53a4bc13998e1ae345db872ee05d7f3a4643
MD5 hash: 99c042f3d73a006576b56754d8f762a1
MIME type:text/plain
Signature GuLoader
File name:style.Nig
File size:23'690 bytes
SHA256 hash: d00b2e33804f03240490ebfcc0292afc26d5928e0f2ab78bc9935751f7dabe15
MD5 hash: 59ef01fdaf669476497bdf5c1723226b
MIME type:application/octet-stream
Signature GuLoader
File name:barkasses.ini
File size:377 bytes
SHA256 hash: 5510770910f6e036e7f7df993430902a967779c8a9e36a5444ca5d4266c5d5dc
MD5 hash: dcf55afe09e6ceb18a2075a48ab873d0
MIME type:text/plain
Signature GuLoader
File name:System.dll
File size:11'264 bytes
SHA256 hash: b80a5cba69d1853ed5979b0ca0352437bf368a5cfb86cb4528edadd410e11352
MD5 hash: c9473cb90d79a374b2ba6040ca16e45c
MIME type:application/x-dosexec
Signature GuLoader
File name:haandbog.jpg
File size:11'395 bytes
SHA256 hash: b997c34097b778f95078fcbffad123921fe7e440ab80c0a0949b3400d67d5dfa
MD5 hash: 718d2f29349ba5dd6e84357811b16352
MIME type:image/jpeg
Signature GuLoader
File name:Afprik.txt
File size:375 bytes
SHA256 hash: 055dff964e697de5f0ea7d8481d1cbf17e7fc559d68ab91e1e1844ff38afbf3c
MD5 hash: 2c135edeac0846a1d02e90106fb21c9a
MIME type:text/plain
Signature GuLoader
File name:Decarbonylating.ini
File size:617 bytes
SHA256 hash: f4e98bd4e106c149436af29c947db82b70652a4a89e586b1275268af9cba3a9d
MD5 hash: 56b71b27ad64be0ec1a380595c54104a
MIME type:text/plain
Signature GuLoader
File name:Vaabenskjoldene.tyv
File size:3'952'614 bytes
SHA256 hash: 0039c787003cb5ee126b0f646d5d3a94b7b44fb2872274213673d2e3b0be7db1
MD5 hash: f1f3c67ee9145e2418cf4b89b15d0faa
MIME type:application/octet-stream
Signature GuLoader
File name:unhearing.txt
File size:361 bytes
SHA256 hash: fd9fe958a116f37215842259f3230d78a9e91cdec21b5eaceefcda0546995c19
MD5 hash: 400e5571fb70c9ac6dd96b62dcf7f0b9
MIME type:text/plain
Signature GuLoader
File name:sunfishery.hyd
File size:6'824'459 bytes
SHA256 hash: 0450bb70e604f924027f68519bb3de9a54495f55ffbb69eaf9bf1f4a21a0ad61
MD5 hash: 68db964f2d11a508d4d9eb84d6129e58
MIME type:application/octet-stream
Signature GuLoader
File name:Centraliseret.jpg
File size:1'869 bytes
SHA256 hash: 8089261977c76892122faa17846bf7157c9d7ff3dc40af920d66ac0913b492ad
MD5 hash: 5c42134f3ee4b7c95165431f1cba887d
MIME type:image/jpeg
Signature GuLoader
File name:skyggefuldt.ref
File size:6'132'232 bytes
SHA256 hash: 9cfea71016ae6f45daab2bd3211994c92bba5285a63d74a57c5e4044a376e61c
MD5 hash: 57bef77e51a043e92e85bdf03a3ce59d
MIME type:application/octet-stream
Signature GuLoader
File name:pigens.jpg
File size:66'213 bytes
SHA256 hash: 597e7ac063eeb916ab3d1b0785365affde0da65dc2fbb7fa5cc48478d2550a30
MD5 hash: 5010f09089e6fe7e8b0e6402b6c00e45
MIME type:image/jpeg
Signature GuLoader
File name:eksporterfaringernes.det
File size:6'203'132 bytes
SHA256 hash: d1c6963858a07c7e5d358b45f153678326e7a013dfe17f4362223db942291299
MD5 hash: 41d07ff3961288dd017c3c63ba4534c9
MIME type:application/octet-stream
Signature GuLoader
File name:opbevaringskapaciteternes.txt
File size:742 bytes
SHA256 hash: a55855b4892d200f42a9cfa799ef202e4c7ff4f80447db3ddf2cf949b6a653d0
MD5 hash: c52c1645730b9c7779d2b20afcdd352e
MIME type:text/plain
Signature GuLoader
File name:Bank Details.bat
File size:1'283'590 bytes
SHA256 hash: f6469663f0a38647f54764309023eefa956a37e381b7b6fabe2882b75464bd8b
MD5 hash: 4198c01c2bd6beb6a9c6276d85aef984
MIME type:application/x-dosexec
Signature GuLoader
File name:Tedesca.jpg
File size:5'629 bytes
SHA256 hash: 7d48b6b48bf64d08abaa4360607266f68f8f254d3d5a766908ce2150e840a8c9
MD5 hash: 33243affcb9c2d8fbc314b6c286291d0
MIME type:image/jpeg
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
70%
Tags:
injection
Result
Verdict:
Suspicious
File Type:
PE File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole guloader installer microsoft_visual_cc nsis overlay unsafe
Verdict:
Malicious
File Type:
7z
First seen:
2025-09-29T08:58:00Z UTC
Last seen:
2025-09-29T08:58:00Z UTC
Hits:
~1000
Detections:
Trojan.Win32.GuLoader.sb Trojan.NSIS.Pakes.Krynis.sb PDM:Trojan.Win32.Generic Trojan-Downloader.Win32.Minix.sb Trojan-Dropper.Win32.Injector.sb Trojan.Win32.Yakes Trojan.NSIS.Makoob.sba Packed.NSIS.Krynis.sb Backdoor.Win32.Remcos.sb VHO:Trojan.Win32.Scarsi.gen HEUR:Trojan.Win32.GuLoader.gen
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-09-29 12:00:04 UTC
File Type:
Binary (Archive)
Extracted files:
19
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:guloader family:remcos discovery downloader installer persistence rat
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
NSIS installer
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Guloader family
Guloader,Cloudeye
Remcos
Remcos family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:pe_detect_tls_callbacks
Rule name:pe_no_import_table
Description:Detect pe file that no import table

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments