MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e727d08263e9aabae9c665e6a70eeba24522af9d299d34e7e8022018f6241602. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 3 File information Comments

SHA256 hash: e727d08263e9aabae9c665e6a70eeba24522af9d299d34e7e8022018f6241602
SHA3-384 hash: 1cf8c51f5e4c3e065ba1c60eece61864684a8e9c4ba7f025b5b0a32162054400df06971a498c785bd51949028718242b
SHA1 hash: 4a0a9a922b91bd296e94b6177097bb337b2418b3
MD5 hash: e4ccdba4d3e5b0331434c63d8282628a
humanhash: arizona-four-delta-berlin
File name:OrdineXdaXclientiXITALIAX-X6320.rar
Download: download sample
Signature GuLoader
File size:111'051 bytes
First seen:2026-07-24 12:15:05 UTC
Last seen:2026-07-24 12:40:53 UTC
File type: rar
MIME type:application/x-rar
ssdeep 3072:NMruXZDnoobDDAIwmprY+/XPxnmyrufOgmnQ5585aVB:N/ZDnoo3DARaxmySmxQ558uB
TLSH T1D4B31258573A4929C60947EB4E8737F39FC12EE51B52067C06DF008A068E7E9264BBF7
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
3
# of downloads :
40
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Ordine da clienti ITALIA - 6320.js
File size:225'747 bytes
SHA256 hash: 791b77c7ccb414a3edf27fc19ad2af606463b520c201f528235e02d9abca2fa8
MD5 hash: e056fe4708e727a783b54f167c455427
MIME type:text/plain
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm base64 cloudeye downloader encrypted fingerprint obfuscated powershell repaired
Verdict:
Malicious
File Type:
rar
First seen:
2026-07-14T09:32:00Z UTC
Last seen:
2026-07-21T15:50:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2026-07-14 16:13:14 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Command and Scripting Interpreter: JavaScript
Drops file in System32 directory
Badlisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Cerberus
Author:Jean-Philippe Teissier / @Jipe_
Description:Cerberus
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar e727d08263e9aabae9c665e6a70eeba24522af9d299d34e7e8022018f6241602

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments