🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cc0a2f02c79accbf94b0f979b33104192d0a7d42d9d18a73b19f0b29ddb03dfd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: cc0a2f02c79accbf94b0f979b33104192d0a7d42d9d18a73b19f0b29ddb03dfd
SHA3-384 hash: a9586078c99cbeb22fc3f6dcc20370b87770e88a3d83c1dac36b9466e4c4a1b2157b4fd419ae21511aa77cfd830f8d1a
SHA1 hash: 5b4c3daad48e97e916d3be3147f3dc6e15e97dee
MD5 hash: 77af3c2364ec32c62336b18983696823
humanhash: sierra-eight-utah-october
File name:SKCMLT17622520986618485758458589457.xlx.z.zip
Download: download sample
Signature GuLoader
File size:4'101 bytes
First seen:2026-05-20 17:07:31 UTC
Last seen:2026-05-20 18:14:28 UTC
File type: zip
MIME type:application/zip
ssdeep 96:RvXUljdzaUVnwQsdz7gSO3Sggc8pAfbbnT:lX4dzVnJsdfgLSgEpAfHnT
TLSH T149816DDE9B3B4F2BD944CDEE0F3640034491671E013AF81684ECA66E9CE3631E246D7A
Magika zip
Reporter TomU
Tags:GuLoader zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
26
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:SKCMLT17622520986618485758458589457.bat
File size:6'977 bytes
SHA256 hash: 1b71f21cbdaadb8658ac8940a4709df3f23dfc9fa6e784d50ebbc7a7888469e2
MD5 hash: cbe72e93c04a891198f9dc0899244b3a
MIME type:text/plain
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
xtreme shell sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 obfuscated powershell
Verdict:
Malicious
File Type:
zip
First seen:
2025-12-01T11:56:00Z UTC
Last seen:
2025-12-01T12:36:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-PowerShell.Trojan.GuLoader
Status:
Malicious
First seen:
2025-12-01 13:48:32 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
17 of 36 (47.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

zip cc0a2f02c79accbf94b0f979b33104192d0a7d42d9d18a73b19f0b29ddb03dfd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments