🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc3deaaae3c218db9c85cf1c19db2392143c71933b41df53ba47fd4588fa6f62. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: dc3deaaae3c218db9c85cf1c19db2392143c71933b41df53ba47fd4588fa6f62
SHA3-384 hash: c4c7ff60735bb6592d78471e7f1bb17cc5d482d129b0287ab9bbfa1106001937743f01c84e51b1998f77587e9711251c
SHA1 hash: f07901330872938a7c44597b69667524952777b8
MD5 hash: 5b79cc9ce75bf0e409fea9178c1dfce1
humanhash: fifteen-river-eighteen-edward
File name:FACTURA.rar
Download: download sample
Signature GuLoader
File size:706'224 bytes
First seen:2026-05-20 18:19:49 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 12288:xofu1XP4t0SEL8riPZvXJE9uSxiPDdYMAPzko6KGGAtSoOL4S9VmgW:hVPyZr0XJE97xir9AKf9OUS7mf
TLSH T15FE423C711D2189C7C885535623C0F688ADE383A427EEC7E78A0EEE54974443ABF6E57
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:FACTURA.exe
File size:841'680 bytes
SHA256 hash: 3b28354d6c2acf81ff156d06417b729a389ff3aec711bb21f6735f8900867014
MD5 hash: a23aa170e907a10108fb73a6ce46f1b7
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
uloader virus nsis blic
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive installer installer installer-heuristic masquerade microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
rar
First seen:
2025-09-18T11:53:00Z UTC
Last seen:
2026-05-14T12:07:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-09-18 21:21:54 UTC
File Type:
Binary (Archive)
Extracted files:
25
AV detection:
23 of 38 (60.53%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar dc3deaaae3c218db9c85cf1c19db2392143c71933b41df53ba47fd4588fa6f62

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments