🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0
SHA3-384 hash: abaa3091db5e5707893ae4417b1576b7c079ba99ea18f2be5b10d6fce878698279cd3c14f0504bac9e75a7849cd625f1
SHA1 hash: 70101dec1e34cb03ac9e8540a05013bf5175fd61
MD5 hash: 41f630848f119363b0d686b48d376650
humanhash: virginia-table-nineteen-california
File name:xshnxyosigj.exe
Download: download sample
Signature GuLoader
File size:36'624 bytes
First seen:2026-01-24 16:51:59 UTC
Last seen:2026-02-07 13:15:20 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 3abe302b6d9a1256e6a915429af4ffd2 (299 x GuLoader, 39 x Formbook, 25 x Loki)
ssdeep 768:4nnw4xRMjJ8FBDOLQmzPjhAVHx10Z0D3yuInmBd0cKp+S:Snw8RSijDtSA5xeZ0DbBCcKpb
TLSH T122F28E1767A0D8FBD57207B0097AAB3BEFFA821411956B0747902F5A7D23583861F393
TrID 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
15.9% (.EXE) Win64 Executable (generic) (10522/11/4)
9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
7.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
6.8% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter aachum
Tags:ccmf-site dropped-by-OffLoader exe GuLoader


Avatar
iamaachum
http://www.ccmf.site/xshnxyosigj.exe

Intelligence


File Origin
# of uploads :
3
# of downloads :
166
Origin country :
ES ES
Vendor Threat Intelligence
Malware configuration found for:
NSIS
Details
NSIS
extracted archive contents
Malware family:
n/a
ID:
1
File name:
xshnxyosigj.exe
Verdict:
No threats detected
Analysis date:
2026-01-24 16:49:30 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
99.1%
Tags:
injection obfusc virus
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis soft-404
Verdict:
Malicious
File Type:
exe x32
First seen:
2019-06-15T09:12:00Z UTC
Last seen:
2026-01-25T00:55:00Z UTC
Hits:
~100000
Detections:
BSS:Trojan.Win32.Truebadur.a
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery installer
Behaviour
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0
MD5 hash:
41f630848f119363b0d686b48d376650
SHA1 hash:
70101dec1e34cb03ac9e8540a05013bf5175fd61
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

GuLoader

Executable exe ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0

(this sample)

  
Dropped by
OffLoader
  
Delivery method
Distributed via web download

Comments