🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e7b37673e8cc1913dbe2f2301cbb146658597b6d1a623a419a5ab2e3efd4c596. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e7b37673e8cc1913dbe2f2301cbb146658597b6d1a623a419a5ab2e3efd4c596
SHA3-384 hash: 262d8a7110f2932193aa433d5cfae097f81cd2e5d4fa3fdc601c56592d2e1a921f4c7046821178d5d18bfd5a853e5dbe
SHA1 hash: 472617197521cc19f5cc13b9321eaee9532e7202
MD5 hash: 1c1f6e1823fb879619265398fa427e80
humanhash: magazine-cup-berlin-wolfram
File name:ORDINI_14393-143480000000000000000045.IMG
Download: download sample
Signature GuLoader
File size:1'507'328 bytes
First seen:2025-11-05 06:24:29 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:SkJk75pc/hoQQE18pKFuzwLvWcgNb8ukJEgr1nugBOHYKdWp4d5sVooWjo8RvSDl:X6pnu+z8YqVpBOHYKdWmwozjo8Rq4NU
TLSH T18D65234D25EAC943F0E45835CF5302F4AE78AE04E9A12617339CBF1EBB78B94D74A245
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter JAMESWT_WT
Tags:ftp-carbognin-it GuLoader img Spam-ITA

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.2%
Tags:
shellcode injector virus nsis
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole context-iso expired-cert installer installer installer-heuristic microsoft_visual_cc nsis overlay overlay packed signed smb
Verdict:
Malicious
File Type:
iso
First seen:
2025-02-13T05:09:00Z UTC
Last seen:
2025-11-04T08:27:00Z UTC
Hits:
~1000
Detections:
HEUR:Trojan-Downloader.Win32.Convagent.gen HEUR:Trojan.Win32.Makoob.gen
Threat name:
Win32.Trojan.Znyonm
Status:
Malicious
First seen:
2025-02-13 11:27:38 UTC
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments