🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cee4d30832970abb49a5167df40135a2bda1d8acaa95312d9804e344e86f7827. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: cee4d30832970abb49a5167df40135a2bda1d8acaa95312d9804e344e86f7827
SHA3-384 hash: 32832d0ade7bfcf810dfbd03be155ea6076f00867ba9b7767e61e433c766bba366a2e2226737693cf8d4e45fa956252e
SHA1 hash: 162e25e8736007bd77fa67ff34c12643a8077179
MD5 hash: 7d860e1ba9548256cdcc7483fc723270
humanhash: uncle-uncle-football-twenty
File name:Objednávka_unitradedoo101425-014010025_docx.vbs
Download: download sample
Signature GuLoader
File size:31'572 bytes
First seen:2025-10-14 11:43:01 UTC
Last seen:2025-10-20 10:44:19 UTC
File type:Visual Basic Script (vbs) vbs
MIME type:text/plain
ssdeep 768:41awbN06MqzdWJfREk2MbkzMoBXzYT5OCtCTN:UTb6qpWZCk2+cU5OAg
TLSH T1A4E293B98C1F4D39EE461BECD81662608C13C17D030229F9ADAF796F8835A3C766D11B
Magika vba
Reporter abuse_ch
Tags:GuLoader vbs

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
SE SE
Vendor Threat Intelligence
Verdict:
Suspicious
Score:
50%
Tags:
obfuscate xtreme spawn
Verdict:
Malicious
File Type:
vbs
First seen:
2025-10-14T06:41:00Z UTC
Last seen:
2025-10-16T07:39:00Z UTC
Hits:
~1000
Detections:
HEUR:Trojan.VBS.SAgent.gen HEUR:Trojan.Script.Generic Trojan.JS.SAgent.sb
Result
Threat name:
Remcos, GuLoader
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Detected Remcos RAT
Disable UAC(promptonsecuredesktop)
Early bird code injection technique detected
Found hidden mapped module (file has been removed from disk)
Installs new ROOT certificates
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Obfuscated command line found
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queues an APC in another process (thread injection)
Searches for Windows Mail specific files
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Remcos
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected GuLoader
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1794738 Sample: W5Zc5u5Er4.vbs Startdate: 14/10/2025 Architecture: WINDOWS Score: 100 58 Suricata IDS alerts for network traffic 2->58 60 Malicious sample detected (through community Yara rule) 2->60 62 Antivirus detection for dropped file 2->62 64 9 other signatures 2->64 8 powershell.exe 4 2->8         started        11 wscript.exe 3 2->11         started        13 powershell.exe 8 2->13         started        15 powershell.exe 2->15         started        process3 signatures4 80 Early bird code injection technique detected 8->80 82 Suspicious powershell command line found 8->82 84 Obfuscated command line found 8->84 92 4 other signatures 8->92 17 msiexec.exe 6 13 8->17         started        86 Wscript starts Powershell (via cmd or directly) 11->86 88 Installs new ROOT certificates 11->88 90 Suspicious execution chain found 11->90 22 powershell.exe 12 6 11->22         started        24 powershell.exe 4 13->24         started        26 powershell.exe 15->26         started        process5 dnsIp6 48 tipsept.ydns.eu 94.198.96.165, 49164, 49165, 49166 ASSEFLOWAmsterdamInternetExchangeAMS-IXIT Italy 17->48 50 cfiwestllc.top 17->50 42 C:\Users\user\AppData\Local\Temp\TH8C1C.tmp, MS-DOS 17->42 dropped 44 C:\Users\user\AppData\Local\Temp\TH846E.tmp, MS-DOS 17->44 dropped 46 C:\Users\user\AppData\Local\Temp\TH3238.tmp, PE32 17->46 dropped 66 Detected Remcos RAT 17->66 68 Obfuscated command line found 17->68 70 Writes to foreign memory regions 17->70 78 4 other signatures 17->78 28 RmClient.exe 1 17->28         started        31 RmClient.exe 11 17->31         started        33 RmClient.exe 17->33         started        35 cmd.exe 17->35         started        52 104.21.23.253, 443, 49162, 49163 CLOUDFLARENETUS United States 22->52 54 cfiwestllc.top 22->54 72 Installs new ROOT certificates 22->72 74 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 22->74 76 Early bird code injection technique detected 24->76 37 msiexec.exe 24->37         started        file7 signatures8 process9 dnsIp10 94 Tries to steal Instant Messenger accounts or passwords 28->94 96 Tries to steal Mail credentials (via file / registry access) 28->96 98 Searches for Windows Mail specific files 28->98 100 Tries to steal Mail credentials (via file registry) 31->100 102 Tries to harvest and steal browser information (history, passwords, etc) 31->102 104 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 31->104 106 Obfuscated command line found 35->106 40 reg.exe 1 35->40         started        56 cfiwestllc.top 37->56 signatures11 process12
Verdict:
inconclusive
YARA:
1 match(es)
Threat name:
Script-WScript.Trojan.Guloader
Status:
Malicious
First seen:
2025-10-14 12:36:48 UTC
File Type:
Text (VBS)
AV detection:
10 of 38 (26.32%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Modifies registry class
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique
Rule name:Guloader_VBScript
Author:Ankit Anubhav - ankitanubhav.info
Description:Detects GuLoader/CloudEye VBScripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments