🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb898ee3c3dcadc6edb794c6ee22c40177431496b4ab6ec00de533ef60838194. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: fb898ee3c3dcadc6edb794c6ee22c40177431496b4ab6ec00de533ef60838194
SHA3-384 hash: 518d1d24fef9047555315e595c65ddf0800853c052af112d4cd1bc9cd8e11914d2a50ba3a38309ff33321d55bb83ed9f
SHA1 hash: 9684ffe38239d24a44b9de4cfddecce7c3c4f19a
MD5 hash: 280bf21321767cf4c0e614e88bd94cdd
humanhash: johnny-alabama-april-seven
File name:REQXNO.88484.rar
Download: download sample
Signature GuLoader
File size:1'098'457 bytes
First seen:2026-05-21 13:57:38 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 24576:svA/6O5KLz+28F7GGzlG6U4evd9q6PUKOP8x:2A3KLz+T7GGzlG6FevhHOP8x
TLSH T1DE3533A038DCE42972BCF1440CEF9EA6CBD535A1AE827650FAB17F6811CE2DD5741C86
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter TomU
Tags:GuLoader rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Noncapture19.exe
File size:1'356'286 bytes
SHA256 hash: c74dc1c9a7dfa5bade8c322a4b5a09f79025b6eabd0956c292b0879417f46f36
MD5 hash: c8d8c1a429d415eee502919a3647e443
MIME type:application/x-dosexec
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
shellcode injection virus
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance
Verdict:
Malicious
File Type:
rar
First seen:
2024-11-08T06:48:00Z UTC
Last seen:
2025-11-13T06:48:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2024-11-06 20:34:25 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
discovery
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Loads dropped DLL
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar fb898ee3c3dcadc6edb794c6ee22c40177431496b4ab6ec00de533ef60838194

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments