🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f338f5aaa23e689ec4e10108c0dd257346435204b07d1a64b34d6b615c22dc50. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: f338f5aaa23e689ec4e10108c0dd257346435204b07d1a64b34d6b615c22dc50
SHA3-384 hash: 50666611cd376ebc872eda2ea93f6107fdee857c88bd6153d3366ccb65951f16a72b9aff98bbacccfe2e5ad163eb8623
SHA1 hash: f2abc6b943c024d4edf465766f9c3a5f668c2441
MD5 hash: 3f8359b0927d42743f0c3ead43c0a312
humanhash: zebra-island-timing-apart
File name:f338f5aaa23e689ec4e10108c0dd257346435204b07d1a64b34d6b615c22dc50
Download: download sample
Signature GuLoader
File size:261'612 bytes
First seen:2026-03-06 14:53:34 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 671f2a1f8aee14d336bab98fea93d734 (204 x GuLoader, 4 x Formbook, 4 x RemcosRAT)
ssdeep 6144:kcBvWb0xvqR7SyzdOnILVkjhjtVeGTpOsUNaCtcGiDFRre:tO0xiR7SYwIRk1XeGOV0CtcBF9e
Threatray 2'475 similar samples on MalwareBazaar
TLSH T1234412E6B161C873E6360F301EB747B63AE7CD122589974333513F5E3E2374A962A261
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon c4dadadad2f492c2 (148 x GuLoader, 51 x RemcosRAT, 23 x VIPKeylogger)
Reporter adrian__luca
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
93.3%
Tags:
uloader virus nsis blic
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis soft-404
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2026-02-16 08:58:47 UTC
File Type:
PE (Exe)
Extracted files:
9
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
phantom_stealer
Score:
  10/10
Tags:
family:phantom_stealer discovery installer stealer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Detects PhantomStealer written in C#
PhantomStealer
Phantom_stealer family
Malware Config
C2 Extraction:
https://api.telegram.org/bot8401696891:AAEYs7_Ah8jc_tbgn-dZ1WL-JuSZ8alyGb8/sendMessage?chat_id=2065242915
Unpacked files
SH256 hash:
f338f5aaa23e689ec4e10108c0dd257346435204b07d1a64b34d6b615c22dc50
MD5 hash:
3f8359b0927d42743f0c3ead43c0a312
SHA1 hash:
f2abc6b943c024d4edf465766f9c3a5f668c2441
SH256 hash:
014f1dfeb842cf7265a3644bc6903c592abe9049bfc7396829172d3d72c4d042
MD5 hash:
12b140583e3273ee1f65016becea58c4
SHA1 hash:
92df24d11797fefd2e1f8d29be9dfd67c56c1ada
SH256 hash:
b2699fdfdab6a018fcc972806d12f71972de1861660bb6578935d62b1da06504
MD5 hash:
3cea4c9994912d8f3c3e8b6a814e810e
SHA1 hash:
c48d34a0981d4ab576c7a3ab566f5ddb94af5d86
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments