🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f4e8fc5b3633b9bbe2246dbdf429e954cef6faa5cccaa0b5494d8f3a0a5849ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: f4e8fc5b3633b9bbe2246dbdf429e954cef6faa5cccaa0b5494d8f3a0a5849ad
SHA3-384 hash: 8dedfeae18d0a14862194e159c04c16461a0daf12d117256eca8df9cdf414fe98f948af8d1fa8e1579f2091d9af8c14a
SHA1 hash: c4ee9fba76827d0df6c5383b9b6887d93adb240f
MD5 hash: d807f790b8f24d99759b44e64d5ac2a3
humanhash: romeo-lamp-lactose-april
File name:FRA00008108000002374.rar
Download: download sample
Signature GuLoader
File size:814'167 bytes
First seen:2026-05-21 13:56:53 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:QBTfjAuooYKHD5r1COPTtWJf1KZYoJyWczxX:OTNoFUEtKCoYd9X
TLSH T1B20533E26061D43973DB0BE6FD4E705E48F02E122E3E4247295FED21930D6F749AA85B
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:FRA00008108000002374.exe
File size:842'864 bytes
SHA256 hash: 24de759c141ec60a2d89352e581ccc47b83d0240702283903e8cbdd1d9745265
MD5 hash: e094f4ca0bcf4795c43c37b71cd65001
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
shellcode virus zbot blic
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive installer installer installer-heuristic microsoft_visual_cc nsis packed reconnaissance signed
Verdict:
Malicious
File Type:
rar
First seen:
2024-11-05T20:48:00Z UTC
Last seen:
2025-10-02T08:33:00Z UTC
Hits:
~100
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2024-11-06 03:33:38 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PE_Digital_Certificate
Author:albertzsigovits

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar f4e8fc5b3633b9bbe2246dbdf429e954cef6faa5cccaa0b5494d8f3a0a5849ad

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments