🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdbf34dd48194d49de0edd54978fa78f23297bf15f9ba44b65d41a0c433cb71c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: fdbf34dd48194d49de0edd54978fa78f23297bf15f9ba44b65d41a0c433cb71c
SHA3-384 hash: 7eaa94f1279cdf84e47a2298b73f8a5aa65cf798895b8b62c319dc0b533d3ae12b8915f34fe1e58a287cef549daed0d8
SHA1 hash: 4dd7e528c48304c18787f336dcb7c2fe183d1d8e
MD5 hash: 640bc5ea8ac5f0eea80e66a9d20341b1
humanhash: zebra-jersey-papa-kitten
File name:pko_trans_details_20250923_124546,pdf.cmd
Download: download sample
Signature GuLoader
File size:4'889 bytes
First seen:2025-10-07 10:56:19 UTC
Last seen:2025-10-09 09:22:13 UTC
File type:cmd cmd
MIME type:text/plain
ssdeep 96:4JLnC3DOtPU6p095tleW5NX/ce9TtgH5mJezghqUOe1uab:4BiD0Prp09/leW5NvceQZmYghqUOpo
TLSH T19AA1637955C63F3EDFCB08A55036C487FA4A01BE4F2A0EF1841FA0B775DA74C6189A94
Magika powershell
Reporter Anonymous
Tags:cmd GuLoader

Intelligence


File Origin
# of uploads :
2
# of downloads :
122
Origin country :
PL PL
Vendor Threat Intelligence
Verdict:
Malicious
Score:
96.5%
Tags:
shell virus sage
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 obfuscated powershell
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-07T03:33:00Z UTC
Last seen:
2025-10-09T08:56:00Z UTC
Hits:
~100
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
92 / 100
Signature
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Obfuscated command line found
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Sigma detected: Potential PowerShell Command Line Obfuscation
Suspicious powershell command line found
Yara detected GuLoader
Yara detected Powershell decode and execute
Behaviour
Behavior Graph:
Threat name:
Script.Trojan.Malgent
Status:
Malicious
First seen:
2025-10-07 08:31:47 UTC
File Type:
Text
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments