🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e98ec2e2ecb0b4c0c6b0d3655e32d6670cf9410c2f9f4826e94a1327c6c2cf8f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: e98ec2e2ecb0b4c0c6b0d3655e32d6670cf9410c2f9f4826e94a1327c6c2cf8f
SHA3-384 hash: 320c3bca76228693474e41529e68301370a68018d5b08e7ced74a45f8e3024869fd7acce571a4162c56d4118425d3d0c
SHA1 hash: 24515ac20886e9cbe91c5ca90beb25e34e11d4da
MD5 hash: 2a43807df407fdf370c866bb642ed088
humanhash: kansas-butter-iowa-stairway
File name:Factura_Honorarios.iso
Download: download sample
Signature GuLoader
File size:1'179'648 bytes
First seen:2026-05-20 18:23:40 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:uz1mihEDmGcmoi6tHnLeJCcAsj3kXdm8L4okLw7rdpAEUdITc1:uz8IEDmvmr2eZxj3yE9zQhpAbIT
TLSH T16245F104FB62AA13C5685B3A49A5D7763B33DD042902D71333ECBE6B7F336926D41286
TrID 47.7% (.ISO/UDF) UDF disc image (2114500/1/6)
46.2% (.NULL) null bytes (2048000/1)
5.7% (.HTP) HomeLab/BraiLab Tape image (256000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
Magika iso
Reporter TomU
Tags:GuLoader iso

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Factura Honorarios.exe
File size:629'037 bytes
SHA256 hash: 6c0377a45f934deee9f135f6132f79ba3ca5c761403533c92f0df5b8709576cb
MD5 hash: 51303f2317cfc9c7b99526371616c2dc
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Malware configuration found for:
Archives NSIS
Details
Archives
extracted archive contents
NSIS
extracted archive contents
Verdict:
Malicious
File Type:
iso
First seen:
2025-07-24T23:32:00Z UTC
Last seen:
2026-04-22T21:55:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-07-25 02:33:53 UTC
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

iso e98ec2e2ecb0b4c0c6b0d3655e32d6670cf9410c2f9f4826e94a1327c6c2cf8f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments