🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6c9d552d1045f7a18903f571524328af4f7d8f297ce9e9b1e43b2fba8bbf8977. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 16


Intelligence 16 IOCs YARA 3 File information Comments

SHA256 hash: 6c9d552d1045f7a18903f571524328af4f7d8f297ce9e9b1e43b2fba8bbf8977
SHA3-384 hash: 9cc56a02b1c90d90794e8e3888bb8bb91e0370c3df49f0c82e27d2c95934cb33a785692637c1770e781a7c0fcb421da5
SHA1 hash: 5cff20e7494330cf92982dbe4d919acccc982b74
MD5 hash: e284ccddd64249cfb245162695ce745e
humanhash: mike-neptune-happy-magnesium
File name:Сделка_33958__EXW_(_Guangzhou_-_ALA)_1_case465KGS.32CBM.exe
Download: download sample
Signature GuLoader
File size:945'528 bytes
First seen:2026-05-20 17:47:53 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 6e7f9a29f2c85394521a08b9f31f6275 (326 x GuLoader, 65 x AgentTesla, 63 x RemcosRAT)
ssdeep 24576:IMwLwUUfyoKLT9aBVob8///jY7aKJ3Q/JJxiRskCocB8He:IMwLwPyoKLTiVA8MyAOB8He
TLSH T1221512417B5C841FC1B405B694B2E29A6BB4ACF0147C93173E397A2F5C383939DAAF16
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon f68b8f83b2b4ec78 (1 x RemcosRAT, 1 x GuLoader)
Reporter TomU
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Overassertively
Issuer:Overassertively
Algorithm:sha256WithRSAEncryption
Valid from:2025-06-01T05:54:07Z
Valid to:2026-09-04T05:54:07Z
Serial number: 6b63544a8f5ec33afc420538603c9e930a3c2e64
Thumbprint Algorithm:SHA256
Thumbprint: bb8ac29806c6f5e563e12dcd808a99c4f0e4988d10b7b9f0eec4acbbff0932a3
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
CH CH
Vendor Threat Intelligence
Malware configuration found for:
GuLoader NSIS
Details
GuLoader
an XOR decryption key and an extracted component
GuLoader
a c2 URL, a useragent string, and a string XOR key
NSIS
extracted archive contents
Malware family:
ID:
1
File name:
Сделка 33958 EXW ( Guangzhou - ALA) 1 case465KGS.32CBM.exe
Verdict:
Malicious activity
Analysis date:
2025-07-18 08:33:25 UTC
Tags:
remcos rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
injection virus blic
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file in the %temp% subdirectories
Creating a file in the %AppData% subdirectories
Creating a file
Delayed reading of the file
Sending a custom TCP request
Restart of the analyzed sample
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Verdict:
Malicious
File Type:
exe x32
First seen:
2025-07-15T07:44:00Z UTC
Last seen:
2026-05-22T05:58:00Z UTC
Hits:
~1000
Result
Threat name:
GuLoader, Remcos
Detection:
malicious
Classification:
troj.evad.phis.spyw
Score:
100 / 100
Signature
AI detected suspicious PE digital signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Connects to many ports of the same IP (likely port scanning)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Uses dynamic DNS services
Writes to foreign memory regions
Yara detected GuLoader
Yara detected Remcos RAT
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1737050 Sample: #U0421#U0434#U0435#U043b#U0... Startdate: 15/07/2025 Architecture: WINDOWS Score: 100 41 denagautr7jkoms1.duckdns.org 2->41 43 makyol.top 2->43 45 geoplugin.net 2->45 59 Suricata IDS alerts for network traffic 2->59 61 Found malware configuration 2->61 63 Antivirus detection for dropped file 2->63 67 14 other signatures 2->67 8 #U0421#U0434#U0435#U043b#U043a#U0430 33958  EXW ( Guangzhou - ALA) 1 case465KGS.32CBM.exe 1 49 2->8         started        signatures3 65 Uses dynamic DNS services 41->65 process4 file5 25 C:\Users\user\AppData\Local\...\nsDialogs.dll, PE32 8->25 dropped 27 C:\Users\user\AppData\Local\...\UserInfo.dll, PE32 8->27 dropped 29 C:\Users\user\AppData\Local\...\System.dll, PE32 8->29 dropped 31 C:\Users\user\AppData\Local\...\BgImage.dll, PE32 8->31 dropped 11 #U0421#U0434#U0435#U043b#U043a#U0430 33958  EXW ( Guangzhou - ALA) 1 case465KGS.32CBM.exe 4 20 8->11         started        process6 dnsIp7 47 denagautr7jkoms1.duckdns.org 104.243.254.100, 18760, 49724, 49725 SOFTLAYERUS United States 11->47 49 makyol.top 104.21.80.1, 443, 49723 CLOUDFLARENETUS United States 11->49 51 geoplugin.net 178.237.33.50, 49726, 80 ATOM86-ASATOM86NL Netherlands 11->51 33 C:\Users\user\AppData\Local\Temp\TH3032.tmp, MS-DOS 11->33 dropped 35 C:\Users\user\AppData\Local\Temp\TH2FD4.tmp, MS-DOS 11->35 dropped 37 C:\Users\user\AppData\Local\Temp\TH2C68.tmp, PE32 11->37 dropped 39 2 other malicious files 11->39 dropped 69 Writes to foreign memory regions 11->69 71 Maps a DLL or memory area into another process 11->71 73 Installs a global keyboard hook 11->73 16 svchost.exe 1 11->16         started        19 svchost.exe 1 11->19         started        21 svchost.exe 2 11->21         started        23 4 other processes 11->23 file8 signatures9 process10 signatures11 53 Tries to steal Instant Messenger accounts or passwords 16->53 55 Tries to harvest and steal browser information (history, passwords, etc) 16->55 57 Tries to steal Mail credentials (via file / registry access) 19->57
Gathering data
Threat name:
Win32.Trojan.GuLoader
Status:
Malicious
First seen:
2025-07-15 13:25:56 UTC
File Type:
PE (Exe)
Extracted files:
21
AV detection:
23 of 36 (63.89%)
Threat level:
  5/5
Result
Malware family:
guloader
Score:
  10/10
Tags:
family:guloader discovery downloader persistence
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Loads dropped DLL
Family: Guloader,Cloudeye
Unpacked files
SH256 hash:
6c9d552d1045f7a18903f571524328af4f7d8f297ce9e9b1e43b2fba8bbf8977
MD5 hash:
e284ccddd64249cfb245162695ce745e
SHA1 hash:
5cff20e7494330cf92982dbe4d919acccc982b74
SH256 hash:
6bf9cccd8a600f4d442efe201e8c07b49605ba35f49a4b3ab22fa2641748e156
MD5 hash:
48f3e7860e1de2b4e63ec744a5e9582a
SHA1 hash:
420c64d802a637c75a53efc8f748e1aede3d6dc6
SH256 hash:
73abbc57661987e7a0aa7e43f6d7dcff63a74615d3b731d94891b05e0e19adcb
MD5 hash:
e2834a37c23a5c487b6e3a55eb95dd8a
SHA1 hash:
2ebc683fe079a8b0081283fd4adfff82f52dfa4d
SH256 hash:
933f93a30ce44df96cbc4ac0b56a8b02ee01da27e4ea665d1d846357a8fca8de
MD5 hash:
98ff85b635d9114a9f6a0cd7b9b649d0
SHA1 hash:
7a51b13aa86a445a2161fa1a567cdaecaa5c97c4
SH256 hash:
7a9ddee34562cd3703f1502b5c70e99cd5bba15de2b6845a3555033d7f6cb2a5
MD5 hash:
564bb0373067e1785cba7e4c24aab4bf
SHA1 hash:
7c9416a01d821b10b2eef97b80899d24014d6fc1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe 6c9d552d1045f7a18903f571524328af4f7d8f297ce9e9b1e43b2fba8bbf8977

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments