🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34f0f347dd07fb4e29258a95972ac9bc6f33fcf0c55166b441affe2ebf57a5b8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 18


Intelligence 18 IOCs YARA 4 File information Comments

SHA256 hash: 34f0f347dd07fb4e29258a95972ac9bc6f33fcf0c55166b441affe2ebf57a5b8
SHA3-384 hash: 0df01ecef03ac34c273e97e3535e4f22febd497bc24e9a28f6f8de4ecc28404d7761e292621797ee8f2b15b7d3684998
SHA1 hash: 844e32e435863018b00400b6dcafde3a609e2a08
MD5 hash: df5292c17a1aa170b553c2d33d730d8e
humanhash: carbon-tennessee-black-snake
File name:Purchase Order Batch 2.exe
Download: download sample
Signature GuLoader
File size:407'128 bytes
First seen:2026-05-11 05:30:54 UTC
Last seen:2026-06-08 09:30:05 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash e2a592076b17ef8bfb48b7e03965a3fc (419 x GuLoader, 63 x RemcosRAT, 52 x AgentTesla)
ssdeep 6144:f4t6LsCB7fXyMBDmJqAZY0wJXMmGcIcU7F+c8TxwLb4njob+Mic28ytlq3rg:fkCBLXy8mqAZUG/eob4nZMicHytCrg
Threatray 2'626 similar samples on MalwareBazaar
TLSH T1478401027E55C413C4B9A2B2CA69EAF6B9148DF4E75E8F4F0EA07FADF8F1141420D259
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon e4e4c0ccd8d2f2da (4 x GuLoader, 1 x RemcosRAT)
Reporter threatcat_ch
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:cithers
Issuer:cithers
Algorithm:sha256WithRSAEncryption
Valid from:2026-04-13T04:41:16Z
Valid to:2027-04-13T04:41:16Z
Serial number: 0ebc36baff7e84ef62538b96da9c8053e839b8d5
Thumbprint Algorithm:SHA256
Thumbprint: 59191daeb638d0c64e17722c0e1879c7f69e9ad4e5517bf858ca5ce20a8d6b73
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
190
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
GuLoader NSIS
Details
GuLoader
an XOR decryption key and an extracted component
GuLoader
a c2 URL, a useragent string, and a string XOR key
NSIS
extracted archive contents
Malware family:
ID:
1
File name:
exe
Verdict:
Malicious activity
Analysis date:
2026-05-11 05:33:03 UTC
Tags:
rat remcos auto-reg remote stealer mpress

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
70%
Tags:
injection obfusc
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Creating a file in the Windows directory
Creating a file in the %temp% directory
Delayed reading of the file
Unauthorized injection to a recently created process
Restart of the analyzed sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug evasive guloader installer installer installer-heuristic masquerade microsoft_visual_cc nsis packed reconnaissance signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-11T00:08:00Z UTC
Last seen:
2026-05-13T03:27:00Z UTC
Hits:
~10000
Detections:
HEUR:Trojan-Downloader.Win32.Minix.gen Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sba Trojan-Downloader.Win32.Minix.sb HEUR:Trojan.NSIS.GuLoader.gen Backdoor.Win32.Remcos.sb
Result
Threat name:
GuLoader, Remcos
Detection:
malicious
Classification:
troj.evad.phis.spyw
Score:
100 / 100
Signature
AI detected suspicious PE digital signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious names
Detected Remcos RAT
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: Remcos
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Writes to foreign memory regions
Yara detected GuLoader
Yara detected Remcos RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1911399 Sample: Purchase Order Batch 2.exe Startdate: 11/05/2026 Architecture: WINDOWS Score: 100 78 drive.usercontent.google.com 2->78 80 drive.google.com 2->80 88 Suricata IDS alerts for network traffic 2->88 90 Found malware configuration 2->90 92 Antivirus detection for dropped file 2->92 94 14 other signatures 2->94 10 Purchase Order Batch 2.exe 35 2->10         started        13 remcos.exe 23 2->13         started        15 remcos.exe 2->15         started        17 rundll32.exe 2->17         started        signatures3 process4 file5 66 C:\Users\user\AppData\Local\...\System.dll, PE32 10->66 dropped 19 Purchase Order Batch 2.exe 2 10 10->19         started        24 Purchase Order Batch 2.exe 10->24         started        68 C:\Users\user\AppData\Local\...\System.dll, PE32 13->68 dropped 26 remcos.exe 6 13->26         started        28 remcos.exe 13->28         started        70 C:\Users\user\AppData\Local\...\System.dll, PE32 15->70 dropped 30 remcos.exe 15->30         started        32 remcos.exe 15->32         started        process6 dnsIp7 82 drive.usercontent.google.com 142.250.65.225, 443, 49756, 49759 GOOGLEUS United States 19->82 84 drive.google.com 142.251.211.110, 443, 49755, 49758 GOOGLEUS United States 19->84 62 C:\ProgramData\Remcos\remcos.exe, PE32 19->62 dropped 64 C:\ProgramData\...\remcos.exe:Zone.Identifier, ASCII 19->64 dropped 114 Detected Remcos RAT 19->114 116 Creates autostart registry keys with suspicious names 19->116 34 remcos.exe 23 19->34         started        38 Purchase Order Batch 2.exe 19->38         started        40 remcos.exe 26->40         started        42 remcos.exe 30->42         started        file8 signatures9 process10 file11 60 C:\Users\user\AppData\Local\...\System.dll, PE32 34->60 dropped 96 Antivirus detection for dropped file 34->96 98 Multi AV Scanner detection for dropped file 34->98 100 Found hidden mapped module (file has been removed from disk) 34->100 102 3 other signatures 34->102 44 remcos.exe 4 10 34->44         started        49 remcos.exe 34->49         started        signatures12 process13 dnsIp14 86 45.9.168.220, 2404, 49760, 49761 GIGANET-HUGigaNetInternetServiceProviderCoHU Hungary 44->86 72 C:\Users\user\AppData\Local\Temp\THA9C8.tmp, MS-DOS 44->72 dropped 74 C:\Users\user\AppData\Local\Temp\THA998.tmp, MS-DOS 44->74 dropped 76 C:\Users\user\AppData\Local\Temp\THA969.tmp, MS-DOS 44->76 dropped 118 Detected Remcos RAT 44->118 120 Writes to foreign memory regions 44->120 122 Maps a DLL or memory area into another process 44->122 51 RmClient.exe 44->51         started        54 RmClient.exe 44->54         started        56 RmClient.exe 44->56         started        58 3 other processes 44->58 file15 signatures16 process17 signatures18 104 Tries to steal Mail credentials (via file registry) 51->104 106 Tries to harvest and steal browser information (history, passwords, etc) 51->106 108 Unusual module load detection (module proxying) 51->108 110 Tries to steal Instant Messenger accounts or passwords 54->110 112 Tries to steal Mail credentials (via file / registry access) 54->112
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable NSIS Installer PE (Portable Executable) PE File Layout Win 32 Exe x86
Threat name:
Win32.Trojan.Qwexlafiba
Status:
Malicious
First seen:
2026-05-11 03:42:36 UTC
File Type:
PE (Exe)
Extracted files:
9
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection discovery persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Adds Run key to start application
Contacts third-party web service commonly abused for C2
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Detected Nirsoft tools
NirSoft MailPassView
Family: Remcos
Malware Config
C2 Extraction:
45.9.168.220:2404
Unpacked files
SH256 hash:
34f0f347dd07fb4e29258a95972ac9bc6f33fcf0c55166b441affe2ebf57a5b8
MD5 hash:
df5292c17a1aa170b553c2d33d730d8e
SHA1 hash:
844e32e435863018b00400b6dcafde3a609e2a08
SH256 hash:
bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
MD5 hash:
17ed1c86bd67e78ade4712be48a7d2bd
SHA1 hash:
1cc9fe86d6d6030b4dae45ecddce5907991c01a0
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 34f0f347dd07fb4e29258a95972ac9bc6f33fcf0c55166b441affe2ebf57a5b8

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments