🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d082bed899d8f975f201975f3c0517debd094cf40630649283de097b0361b8fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Guildma


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: d082bed899d8f975f201975f3c0517debd094cf40630649283de097b0361b8fc
SHA3-384 hash: d23c6c493c64691e67d8807b4cb990db01b098a5cf60f6625b434412bee42aca64c9578767e1847700216a1aee6ac325
SHA1 hash: 3bf922314f250b156b7a1fdf2e5a025e59160982
MD5 hash: 9766a65884177f26090aeca0a6247865
humanhash: wolfram-snake-social-arkansas
File name:solicitado52
Download: download sample
Signature Guildma
File size:56'369'152 bytes
First seen:2026-10-07 21:03:53 UTC
Last seen:Never
File type:Microsoft Software Installer (MSI) msi
MIME type:application/x-msi
ssdeep 786432:NzMvQBrCCdpr2FziVoJaHsN0tz4G6dDbmWWQAzYpVmcRzySr196bHVa7/VVYka/5:KueLFzEoJyc0mDb7M8pkcRMbk7/VVSG
TLSH T17FC73326A19A8F7DDBC8A63CAC8A504C984B2F05CC141A15E19FFE788673143B1B7E95
TrID 86.8% (.MSI) Microsoft Windows Installer (454500/1/170)
11.6% (.MST) Windows SDK Setup Transform script (61000/1/5)
1.5% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika msi
Reporter johnk3r
Tags:Astaroth banker contabilidadeacportela-net controedatoerpestanavidroslat-com guildma hggdconfeccoesgruponacional-click msi saladeouroriopreto-shop signed

Code Signing Certificate

Organisation:Global InnvT
Issuer:Global InnvT
Algorithm:sha256WithRSAEncryption
Valid from:2026-10-07T12:06:45Z
Valid to:2027-10-07T12:26:45Z
Serial number: 5d0322e67cbe0bb2454b0bf8f77c1849
Thumbprint Algorithm:SHA256
Thumbprint: 8bd85a79061a4ff96a4185cd39a0c89350de5394467af5ac7d45718be7126906
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
105
Origin country :
BR BR
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug expired-cert fingerprint installer keylogger reconnaissance signed
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
AI detected suspicious PE / MSI digital signature
Allocates memory in foreign processes
Antivirus detection for URL or domain
Drops PE files with benign system names
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Suricata IDS alerts for network traffic
System process connects to network (likely due to code injection or exploit)
Tries to delay execution (extensive OutputDebugStringW loop)
Writes to foreign memory regions
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1983869 Sample: solicitado52.msi Startdate: 07/10/2026 Architecture: WINDOWS Score: 100 53 controedatoerpestanavidroslat.com 2->53 55 vip-imap-az.eastus2.cloudapp.azure.com 2->55 57 6 other IPs or domains 2->57 67 Suricata IDS alerts for network traffic 2->67 69 Antivirus detection for URL or domain 2->69 71 Multi AV Scanner detection for submitted file 2->71 73 4 other signatures 2->73 9 msiexec.exe 87 43 2->9         started        13 cmd.exe 1 2->13         started        15 cmd.exe 2->15         started        17 msiexec.exe 3 2->17         started        signatures3 process4 file5 45 C:\Fworksdsysm\en8kgxcZ08wf\explorer.exe, PE32 9->45 dropped 47 C:\Fworksdsysm\en8kgxcZ08wf\svchost_sys.log, ASCII 9->47 dropped 49 C:\Fworksdsysm\en8kgxcZ08wf\ssleay32.dll, PE32 9->49 dropped 51 2 other files (none is malicious) 9->51 dropped 77 Injects code into the Windows Explorer (explorer.exe) 9->77 19 explorer.exe 1 9->19         started        22 explorer.exe 1 13->22         started        24 conhost.exe 13->24         started        26 explorer.exe 1 15->26         started        28 conhost.exe 15->28         started        79 Drops PE files with benign system names 17->79 signatures6 process7 signatures8 75 Tries to delay execution (extensive OutputDebugStringW loop) 19->75 30 explorer.exe 5 1 19->30         started        34 explorer.exe 22->34         started        36 explorer.exe 26->36         started        process9 dnsIp10 63 controedatoerpestanavidroslat.com 151.243.137.99, 443, 49715 CDNEXTGB Brazil 30->63 65 api.ipify.org 104.26.12.205, 443, 49714 CLOUDFLARENET-CloudflareIncUS Canada 30->65 81 System process connects to network (likely due to code injection or exploit) 30->81 83 Writes to foreign memory regions 30->83 85 Allocates memory in foreign processes 30->85 38 RegSvcs.exe 2 3 30->38         started        41 RegSvcs.exe 3 34->41         started        87 Injects a PE file into a foreign processes 36->87 43 RegSvcs.exe 3 36->43         started        signatures11 process12 dnsIp13 59 185.101.104.27, 49717, 49719, 49721 OVHFR Canada 38->59 61 vip-imap-az.eastus2.cloudapp.azure.com 20.157.67.141, 49716, 49718, 49720 MICROSOFT-CORP-MSN-AS-BLOCK-MicrosoftCorporationUS United States 38->61
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery persistence privilege_escalation ransomware
Behaviour
Checks SCSI registry key(s)
Checks processor information in registry
NTFS ADS
Script User-Agent
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Volume Shadow Copy service COM API
Event Triggered Execution: Installer Packages
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Windows directory
Adds Run key to start application
Badlisted process makes network request
Enumerates connected drives
Looks up external IP address via web service
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Guildma

Microsoft Software Installer (MSI) msi d082bed899d8f975f201975f3c0517debd094cf40630649283de097b0361b8fc

(this sample)

Comments