🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d6aca141b788e7023a358e12fb9037b7e737d5b4d1b44e883f020104ffba003b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 10


Intelligence 10 IOCs YARA 4 File information Comments

SHA256 hash: d6aca141b788e7023a358e12fb9037b7e737d5b4d1b44e883f020104ffba003b
SHA3-384 hash: 77c6c7010eb2fd3f623cd10776315b65a9980c0b529cdd71169d5d7f380edac028c18fb19f4368f9e8cd76ad8314a0f4
SHA1 hash: 466c75b866982896884cc7a4ba898b407eb61d81
MD5 hash: 438c88907942d589c64024b8746260de
humanhash: equal-leopard-batman-fish
File name:MT103 SWIFT COPY.7z
Download: download sample
Signature GuLoader
File size:361'828 bytes
First seen:2025-09-24 03:32:10 UTC
Last seen:Never
File type: 7z
MIME type:application/x-7z-compressed
ssdeep 6144:xontU7ruEjxt5YkCUg9HaQBOKLUxjo+Hb20M/ohch4YkdZ69OCSPKY6JSh:xx1Yyg96QBB05y5bJkTUOtPLwSh
TLSH T19D742349ACF04A51C8DEDA05298CFB75DB15091F26ECE842E57BF2537CB84A67F00E26
TrID 57.1% (.7Z) 7-Zip compressed archive (v0.4) (8000/1)
42.8% (.7Z) 7-Zip compressed archive (gen) (6000/1)
Magika sevenzip
Reporter JAMESWT_WT
Tags:7z GuLoader Spam-ITA

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:MT103 SWIFT COPY.exe
File size:385'568 bytes
SHA256 hash: 658e1034df7e4b35e11fb4403be312fa834bccce8c381b81b6623dfc26a9a2cf
MD5 hash: 3cabe118b8b13417947ab71f331188ea
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
injection obfusc blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole guloader installer microsoft_visual_cc nsis overlay signed unsafe
Verdict:
Malicious
File Type:
7z
First seen:
2025-09-23T23:31:00Z UTC
Last seen:
2025-09-23T23:31:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.GuLoader.sb Trojan.NSIS.Pakes.Krynis.sb HEUR:Trojan.Win32.GuLoader.gen Trojan.NSIS.Makoob.sba Packed.NSIS.Krynis.sb
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
7z Archive Executable PE (Portable Executable) PE File Layout SFX 7z
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-09-23 15:15:02 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:guloader discovery downloader
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Loads dropped DLL
Guloader family
Guloader,Cloudeye
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments