🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a06d2f622eb4e0403f8a8198898d2ae1d26b5f897cedadcb68cc95b888dc7525. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 17


Intelligence 17 IOCs YARA 2 File information Comments

SHA256 hash: a06d2f622eb4e0403f8a8198898d2ae1d26b5f897cedadcb68cc95b888dc7525
SHA3-384 hash: bada6af9da454ed342d1f918650a85aaac56b53351e75bb5e73e652924629485dadb07cb8addcf5d475aa38274a18811
SHA1 hash: 4fcd7233a913288e83af1c4ebff7ec085634d421
MD5 hash: 117bc638988d7009c17f5f835580d83a
humanhash: robert-india-neptune-mississippi
File name:Quotation_Request.exe
Download: download sample
Signature GuLoader
File size:645'314 bytes
First seen:2026-03-27 08:04:23 UTC
Last seen:2026-03-27 08:29:22 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ced282d9b261d1462772017fe2f6972b (129 x Formbook, 124 x GuLoader, 72 x RemcosRAT)
ssdeep 12288:r0yeHMloKEZaf7HrBp+WkvbBN2u4ByUVTAGZ3LUbBLGCR2pUOos7gARuS:MHGfTrBp0vdcByArJ+2pBgO
Threatray 3'316 similar samples on MalwareBazaar
TLSH T185D42328EAA3F89CE95C41B13D724712D7E5AF683B2C1D471FC17BA161FE886D62C601
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon f4926b29736d2790 (2 x GuLoader)
Reporter lowmal3
Tags:exe GuLoader

Intelligence


File Origin
# of uploads :
3
# of downloads :
189
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
Quotation_Request.exe
Verdict:
Malicious activity
Analysis date:
2026-03-27 01:11:52 UTC
Tags:
rat remcos remote

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
91.7%
Tags:
injection obfusc blic
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Creating a file in the %AppData% subdirectories
Creating a file in the %temp% directory
Delayed reading of the file
Unauthorized injection to a recently created process
Restart of the analyzed sample
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole installer installer installer-heuristic microsoft_visual_cc nsis soft-404 unsafe
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-03-26T20:26:00Z UTC
Last seen:
2026-03-29T06:21:00Z UTC
Hits:
~1000
Detections:
Trojan.NSIS.Makoob.sba Trojan.Win32.Delikle.sb PDM:Trojan.Win32.Generic HEUR:Trojan-Downloader.Win32.Minix.gen Trojan-Downloader.Win32.Minix.sb Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sbd
Result
Threat name:
Remcos, GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious names
Detected Remcos RAT
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Initial sample is a PE file and has a suspicious name
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Unusual module load detection (module proxying)
Yara detected GuLoader
Yara detected Remcos RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1890039 Sample: Quotation_Request.exe Startdate: 27/03/2026 Architecture: WINDOWS Score: 100 52 107.172.13.233 AS-COLOCROSSINGUS United States 2->52 54 drive.usercontent.google.com 2->54 56 drive.google.com 2->56 62 Found malware configuration 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 Yara detected GuLoader 2->66 68 3 other signatures 2->68 9 Quotation_Request.exe 4 53 2->9         started        13 remcos.exe 29 2->13         started        15 remcos.exe 20 2->15         started        17 remcos.exe 2->17         started        signatures3 process4 file5 44 C:\Users\user\AppData\Local\...\System.dll, PE32 9->44 dropped 46 C:\Users\user\AppData\Roaming\...\Dikamalli, data 9->46 dropped 76 Tries to detect virtualization through RDTSC time measurements 9->76 78 Unusual module load detection (module proxying) 9->78 80 Switches to a custom stack to bypass stack traces 9->80 19 Quotation_Request.exe 2 10 9->19         started        24 Quotation_Request.exe 9->24         started        48 C:\Users\user\AppData\Local\...\System.dll, PE32 13->48 dropped 82 Found direct / indirect Syscall (likely to bypass EDR) 13->82 26 remcos.exe 13->26         started        28 remcos.exe 13->28         started        signatures6 process7 dnsIp8 58 drive.usercontent.google.com 142.251.214.161, 443, 49701 GOOGLEUS United States 19->58 60 drive.google.com 142.251.35.238, 443, 49700 GOOGLEUS United States 19->60 40 C:\ProgramData\Remcos\remcos.exe, PE32 19->40 dropped 42 C:\ProgramData\...\remcos.exe:Zone.Identifier, ASCII 19->42 dropped 70 Detected Remcos RAT 19->70 72 Creates autostart registry keys with suspicious names 19->72 74 Found direct / indirect Syscall (likely to bypass EDR) 19->74 30 remcos.exe 29 19->30         started        34 Quotation_Request.exe 19->34         started        file9 signatures10 process11 file12 50 C:\Users\user\AppData\Local\...\System.dll, PE32 30->50 dropped 84 Multi AV Scanner detection for dropped file 30->84 86 Tries to detect virtualization through RDTSC time measurements 30->86 88 Switches to a custom stack to bypass stack traces 30->88 90 Found direct / indirect Syscall (likely to bypass EDR) 30->90 36 remcos.exe 20 30->36         started        38 remcos.exe 30->38         started        signatures13 process14
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-03-27 01:25:49 UTC
File Type:
PE (Exe)
Extracted files:
21
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost discovery installer persistence rat
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
NSIS installer
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Contacts third-party web service commonly abused for C2
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Remcos
Remcos family
Malware Config
C2 Extraction:
107.172.13.233:2404
Unpacked files
SH256 hash:
d09a8b3ade4ba4b7292c0b3da1bcb4b6c6e2012e0ccfd5e029a54af73a9e1b57
MD5 hash:
4ca4fd3fbefa2f6e87e6e9ee87d1c0b3
SHA1 hash:
7cdbeb5ff2b14b86af04e075d0ca651183ea5df4
SH256 hash:
d253ca5aba34b925796777893f114cc741b015af7868022ab1db2341288c55ed
MD5 hash:
eb2c74e05b30b29887b3219f4ea3fdab
SHA1 hash:
91173d46b34e7bae57acabdbd239111b5bcc4d9e
SH256 hash:
a06d2f622eb4e0403f8a8198898d2ae1d26b5f897cedadcb68cc95b888dc7525
MD5 hash:
117bc638988d7009c17f5f835580d83a
SHA1 hash:
4fcd7233a913288e83af1c4ebff7ec085634d421
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe a06d2f622eb4e0403f8a8198898d2ae1d26b5f897cedadcb68cc95b888dc7525

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments