🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f885bb0ae6fd73569aa017c144d9e064cf898d9e28a2eca21c65c4e8cf5f21ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: f885bb0ae6fd73569aa017c144d9e064cf898d9e28a2eca21c65c4e8cf5f21ab
SHA3-384 hash: df78912fcef8a333a916a5092359670b2152f4f079c4bc67d99a4f3f419a54e2e35459aff38c850f7541f6cfa58ee550
SHA1 hash: 23c393e2d90ce493b5cbb3df5f7d51fdc88a1c2b
MD5 hash: 3f9b9ce7b2d4f05c356f7b82a0bf3648
humanhash: west-william-monkey-freddie
File name:AGC768-25-09-22.rar
Download: download sample
Signature GuLoader
File size:799'341 bytes
First seen:2026-05-20 18:27:23 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:ASpuzZHrtOfZb5tWeM+/Ll+ZGVc7h4kxMa7uYOREW1:rpWHrtOfsxGlsG8+Hb1
TLSH T1D40523F9BF8E39747A168B50203517B96F2FC14C46A895F04379EAA3DCEF4296C8065C
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
CH CH
File Archive Information

This file archive contains 18 file(s), sorted by their relevance:

File name:Bijectively.cov
File size:1'319'896 bytes
SHA256 hash: 943fb659b7cfa50834cfe5ae90a62cbf1dbe0d59fc80490e29f7985212104399
MD5 hash: 7258b58209339f7b900062b8ad282b3e
MIME type:application/octet-stream
Signature GuLoader
File name:Vasoganglion132.ini
File size:490 bytes
SHA256 hash: 3f72ca4e289d6a5d2572c7990f8e6c1a8c44a247a8764ce6ea868ab771966a90
MD5 hash: 24b367d16a1251dda65781925f301e41
MIME type:text/plain
Signature GuLoader
File name:patter.txt
File size:487 bytes
SHA256 hash: 990e3010eb1eb2d7f9c736016d5e2ec4d5af4b5f2f5cb2dbfb9ba5340bb3f334
MD5 hash: 14c29aa0b6a1626565b1767778cc7be2
MIME type:text/plain
Signature GuLoader
File name:System.dll
File size:12'288 bytes
SHA256 hash: a44ca08afb3f6bafd76aa35c259f3d599fe34f6f49ea5118626c1c1a540b0f03
MD5 hash: 81e268e27dbbcadbf116b5a9402195ab
MIME type:application/x-dosexec
Signature GuLoader
File name:hemmelige.jpg
File size:30'054 bytes
SHA256 hash: f8775c02fc892e18a1a3ca1a52513a62d6587d25d5ef1ab47c7e3fba0182c6da
MD5 hash: 124f8a2e7151c374ae6929a1fc8b5c65
MIME type:image/jpeg
Signature GuLoader
File name:anglicism.sne
File size:4'285'224 bytes
SHA256 hash: 24bf5ad8e162ec2e26e7e82760e6810dab04d27813599232ef6b3f8d48bf99f4
MD5 hash: 02e95ed3d5847e325a6ffc4bdbb55396
MIME type:application/octet-stream
Signature GuLoader
File name:Quietest.Ind
File size:23'639 bytes
SHA256 hash: 799d3242cd52de657ae2878b4943811d6582a20d50478f1be17bc67fb43ce7ca
MD5 hash: b0f49a78b64dca651ce022801b82bd0a
MIME type:application/octet-stream
Signature GuLoader
File name:Kvikslvtermometrenes.pro
File size:2'003'105 bytes
SHA256 hash: f2fae98d55d4143e6520e8ff5dc51a1469269cd2510f2b4d563807e7e65c30e1
MD5 hash: 894764a9e45f4fcef60d21dd29eb5659
MIME type:application/octet-stream
Signature GuLoader
File name:alkymistiske.ini
File size:438 bytes
SHA256 hash: e6d86f472c44911cd5de61f249bca154f0d713e2aef2ec56e68b6a33f033ce40
MD5 hash: c9d4be0e73d54c07a952376eeb05f43e
MIME type:application/x-wine-extension-ini
Signature GuLoader
File name:AGC768-25-09-22.scr
File size:831'072 bytes
SHA256 hash: aea137eae4b972ffbecdedc149a7ba4c1b40dbe4958ec6209acb734998bbfe15
MD5 hash: 8685603343420def0aa0a7b27bc8c476
MIME type:application/x-dosexec
Signature GuLoader
File name:mesaconic.sob
File size:1'707'852 bytes
SHA256 hash: 8614fbfa7fcad57d9c314b95c0cf9e7eed54baa457a806b26b8448f9b5af5a2f
MD5 hash: 2bc3ec8a83ad650acda602e82623aad1
MIME type:image/x-tga
Signature GuLoader
File name:choripetalous.ini
File size:221 bytes
SHA256 hash: 6b18f436195e77b11eaa0aec2a2dde372952105ea91709ca00cddabd4ed72abe
MD5 hash: a3b9b17fc811ba32ee083d4c3916c3c8
MIME type:text/plain
Signature GuLoader
File name:nsDialogs.dll
File size:9'728 bytes
SHA256 hash: 7853be9190489ba84dae8232e9a967cec02d941732cb4137bc9ae6a392e89fb8
MD5 hash: 3fbd78c889fa40a2e5567b980c57b7db
MIME type:application/x-dosexec
Signature GuLoader
File name:Overfrown.Afp
File size:335'584 bytes
SHA256 hash: e159875a647994fa4dae22f38a5594b7571bbe45e6cb4571ad1166f7b1001352
MD5 hash: 4941c82776179efea5d9f763a174ad47
MIME type:application/octet-stream
Signature GuLoader
File name:glatkrsel.jpg
File size:16'188 bytes
SHA256 hash: 465395428ab4c42c9cd2f9b0c59b1707e7fac31efacae31715a2847aa57fcbd3
MD5 hash: e58dfecdcfaeaab52a23638e59da9a85
MIME type:image/jpeg
Signature GuLoader
File name:irrationalizes.ini
File size:393 bytes
SHA256 hash: 289e1516a1f0cb2c0300356f0ae760d8fc83b4176e26ecc11d19682455824ab8
MD5 hash: fd476393331695e69b17a874fdf573bd
MIME type:text/plain
Signature GuLoader
File name:vrelserne.txt
File size:181 bytes
SHA256 hash: 479e6b2ab95cf13ba6939ab259ce688bbb8e2ab2875e9a866431e868757a1ab8
MD5 hash: ecf9c96e5263555377b815fb2e80aff2
MIME type:text/plain
Signature GuLoader
File name:sjlehal.jpg
File size:109'717 bytes
SHA256 hash: 2efee78da871e94ce57ecbb0b3c3ce20e8fd08255359427949863d94b3596e59
MD5 hash: 5c641d6b1159a2a40bb287a1c2f9bf23
MIME type:image/jpeg
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
injection obfusc virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
rar
First seen:
2025-09-22T19:00:00Z UTC
Last seen:
2026-05-20T14:41:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2025-09-22 22:49:18 UTC
File Type:
Binary (Archive)
Extracted files:
18
AV detection:
26 of 37 (70.27%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar f885bb0ae6fd73569aa017c144d9e064cf898d9e28a2eca21c65c4e8cf5f21ab

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments