🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fcb4d66581a1c4eb0e79509fbc7bca6ae75bb1a9fa8386f4ac2d8e224596258c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: fcb4d66581a1c4eb0e79509fbc7bca6ae75bb1a9fa8386f4ac2d8e224596258c
SHA3-384 hash: 04c5bb4fdf14ffc252bc14e29a73f1a199aab38b88a9ce0ad8a4de65daf9d63d96cc86ec30af344c49bf315afc19978e
SHA1 hash: d909d1107a1b0bb4ac195019ea97d2aaf2615d36
MD5 hash: 6a63b7ff16064c03423738879df87460
humanhash: white-three-pip-grey
File name:Payment_Confirmation 900811865 Remittance_Copy_2025-12-11_pdf.txz
Download: download sample
Signature GuLoader
File size:33'370 bytes
First seen:2025-12-12 23:37:34 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 768:Y62j2GY5A2+eaUt/MSylNRFeqKLQ77QdkuybwVPFwv8ABNgU:Y6LGaA2P1MSceqwSikuc0q8wX
TLSH T11FE2F17E6B3C68F9FA3C8C3FF0C4A57A0C598225B326A4562DB135394987ACCC617E05
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter cocaman
Tags:Gu GuLoader INVOICE payment rar txz


Avatar
cocaman
Malicious email (T1566.001)
From: "Natalie ZHUO | Unit-Match<export@handybiotech.com>" (likely spoofed)
Received: "from mail.handybiotech.com (mail.handybiotech.com [198.46.233.88]) "
Date: "12 Dec 2025 15:37:18 -0800"
Subject: "RE: Invoice No..."
Attachment: "Payment_Confirmation 900811865 Remittance_Copy_2025-12-11_pdf.txz"

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Payment_Confirmation 900811865 Remittance_Copy_2025-12-11_pdf.js
File size:598'327 bytes
SHA256 hash: d1a983df0b264704e5c79e46dab5a17c1379a010e93bd610afcce23cd72c05bd
MD5 hash: a99607f9f10448b7f2a89461475cdbb1
MIME type:text/plain
Signature GuLoader
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
infosteal
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
cloudeye fingerprint masquerade powershell repaired
Verdict:
Malicious
File Type:
rar
First seen:
2025-12-12T20:26:00Z UTC
Last seen:
2025-12-13T11:44:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
1 match(es)
Tags:
Rar Archive
Threat name:
Win32.Trojan.Guloader
Status:
Malicious
First seen:
2025-12-12 11:08:47 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
15 of 38 (39.47%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

rar fcb4d66581a1c4eb0e79509fbc7bca6ae75bb1a9fa8386f4ac2d8e224596258c

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments