MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
GuLoader
Vendor detections: 11
| SHA256 hash: | ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0 |
|---|---|
| SHA3-384 hash: | abaa3091db5e5707893ae4417b1576b7c079ba99ea18f2be5b10d6fce878698279cd3c14f0504bac9e75a7849cd625f1 |
| SHA1 hash: | 70101dec1e34cb03ac9e8540a05013bf5175fd61 |
| MD5 hash: | 41f630848f119363b0d686b48d376650 |
| humanhash: | virginia-table-nineteen-california |
| File name: | xshnxyosigj.exe |
| Download: | download sample |
| Signature | GuLoader |
| File size: | 36'624 bytes |
| First seen: | 2026-01-24 16:51:59 UTC |
| Last seen: | 2026-02-07 13:15:20 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 3abe302b6d9a1256e6a915429af4ffd2 (299 x GuLoader, 39 x Formbook, 25 x Loki) |
| ssdeep | 768:4nnw4xRMjJ8FBDOLQmzPjhAVHx10Z0D3yuInmBd0cKp+S:Snw8RSijDtSA5xeZ0DbBCcKpb |
| TLSH | T122F28E1767A0D8FBD57207B0097AAB3BEFFA821411956B0747902F5A7D23583861F393 |
| TrID | 47.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13) 15.9% (.EXE) Win64 Executable (generic) (10522/11/4) 9.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 7.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 6.8% (.EXE) Win32 Executable (generic) (4504/4/1) |
| Magika | pebin |
| dhash icon | b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla) |
| Reporter | |
| Tags: | ccmf-site dropped-by-OffLoader exe GuLoader |
Intelligence
File Origin
# of uploads :
3
# of downloads :
166
Origin country :
ESVendor Threat Intelligence
Malware configuration found for:
NSIS
Details
NSIS
extracted archive contents
Malware family:
n/a
ID:
1
File name:
xshnxyosigj.exe
Verdict:
No threats detected
Analysis date:
2026-01-24 16:49:30 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Detection(s):
Verdict:
Malicious
Score:
99.1%
Tags:
injection obfusc virus
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis soft-404
Verdict:
Malicious
Labled as:
Win/grayware_confidence_70%
Verdict:
Malicious
File Type:
exe x32
First seen:
2019-06-15T09:12:00Z UTC
Last seen:
2026-01-25T00:55:00Z UTC
Hits:
~100000
Detections:
BSS:Trojan.Win32.Truebadur.a
Verdict:
Malicious
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Multi AV Scanner detection for submitted file
Behaviour
Behavior Graph:
Score:
77%
Verdict:
Malware
File Type:
PE
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Verdict:
Malicious
Threat:
Family.GULOADER
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
3/10
Tags:
discovery installer
Behaviour
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Unpacked files
SH256 hash:
ea37950d79a6a7cde271a8d59a222aa4f0f34d3fb08501d9fa9eaee89fe192d0
MD5 hash:
41f630848f119363b0d686b48d376650
SHA1 hash:
70101dec1e34cb03ac9e8540a05013bf5175fd61
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Trojan
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Dropped by
OffLoader
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.