🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9624e6bd4e2336c04ac9a5ccbb67a5f66312528fa839547e4a543f12aa46ad5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 15


Intelligence 15 IOCs YARA 4 File information Comments

SHA256 hash: c9624e6bd4e2336c04ac9a5ccbb67a5f66312528fa839547e4a543f12aa46ad5
SHA3-384 hash: 2d7f75dcbc3f913a6035810f8d580f8a9a0777a63983a1e0ecbe24f4d515a58dd12d785b45292cc26adbf08dc450cb70
SHA1 hash: 9e3b5d55d1d97611ba8fca903eb8bddf8a9b0810
MD5 hash: 86666c4287b523e0b80c14dbda780f08
humanhash: uniform-early-washington-seven
File name:RFQ# RE-7.1210594.exe
Download: download sample
Signature GuLoader
File size:880'608 bytes
First seen:2026-05-21 07:27:24 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 9a16e282eba7cc710070c0586c947693 (37 x GuLoader, 15 x RemcosRAT, 11 x VIPKeylogger)
ssdeep 24576:hv6Dmf5/CEa+Q1NQhaM6gpmaITJXe+56LqgBA:8qR6D1ir6gM1f8BA
Threatray 133 similar samples on MalwareBazaar
TLSH T160152392FB60E967D490DDB24CB4F02E47E7EC40D9A5870AFB01B64AF83C5C5994E722
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon f89ca4540dcce132 (3 x RemcosRAT, 1 x GuLoader)
Reporter lowmal3
Tags:exe GuLoader signed

Code Signing Certificate

Organisation:Vikingernes
Issuer:Vikingernes
Algorithm:sha256WithRSAEncryption
Valid from:2026-04-03T03:11:18Z
Valid to:2027-04-03T03:11:18Z
Serial number: 08155a935b03da1aed704c0134aa4f9a695d0cde
Thumbprint Algorithm:SHA256
Thumbprint: a126a75dd6794179dfe88076435e0d296b952feb261577d56e4813fc6bb25f02
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
187
Origin country :
DE DE
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
_c9624e6bd4e2336c04ac9a5ccbb67a5f66312528fa839547e4a543f12aa46ad5.exe
Verdict:
Malicious activity
Analysis date:
2026-05-21 07:30:43 UTC
Tags:
remcos rat

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
81.4%
Tags:
injection obfusc sage
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Creating a file
Creating a file in the %AppData% directory
Delayed reading of the file
Creating a file in the %temp% subdirectories
Searching for the Windows task manager window
Running batch commands
Creating a process with a hidden window
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug fingerprint installer installer installer-heuristic microsoft_visual_cc nsis reconnaissance signed
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-05-21T00:03:00Z UTC
Last seen:
2026-05-22T20:15:00Z UTC
Hits:
~100
Detections:
Trojan.NSIS.Makoob.tn Trojan.Win32.Guloader.sb Trojan.NSIS.Makoob.sbb Trojan.NSIS.Makoob.sba Trojan-Downloader.Win32.Minix.sb
Result
Threat name:
GuLoader, Remcos
Detection:
malicious
Classification:
troj.evad.spyw
Score:
100 / 100
Signature
AI detected suspicious PE digital signature
C2 URLs / IPs found in malware configuration
Contains functionality to steal Internet Explorer form passwords
Detected Remcos RAT
Found malware configuration
Initial sample is a PE file and has a suspicious name
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Mass process execution to delay analysis
Multi AV Scanner detection for submitted file
Obfuscated command line found
Sigma detected: Remcos
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Yara detected GuLoader
Yara detected Remcos RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1916950 Sample: RFQ# RE-7.1210594.exe Startdate: 21/05/2026 Architecture: WINDOWS Score: 100 49 www.google.com 2->49 51 drive.usercontent.google.com 2->51 53 drive.google.com 2->53 59 Found malware configuration 2->59 61 Multi AV Scanner detection for submitted file 2->61 63 Yara detected GuLoader 2->63 65 13 other signatures 2->65 8 RFQ# RE-7.1210594.exe 1 46 2->8         started        signatures3 process4 file5 37 C:\Users\user\AppData\Local\...\nsExec.dll, PE32 8->37 dropped 39 C:\Users\user\AppData\Local\...\System.dll, PE32 8->39 dropped 67 Obfuscated command line found 8->67 12 RFQ# RE-7.1210594.exe 4 12 8->12         started        17 cmd.exe 8->17         started        19 cmd.exe 8->19         started        21 63 other processes 8->21 signatures6 process7 dnsIp8 55 204.10.160.191, 2404, 49760, 49761 UNREAL-SERVERS-UnRealServersLLCUS United States 12->55 57 drive.usercontent.google.com 142.250.191.1, 443, 49759 GOOGLE-GoogleLLCUS United States 12->57 41 C:\Users\user\AppData\...\Login Data.tmp, SQLite 12->41 dropped 43 C:\Users\user\AppData\...\Login Data.tmp, SQLite 12->43 dropped 45 C:\Users\user\...\Login Data For Account.tmp, SQLite 12->45 dropped 47 C:\ProgramData\remcos\logs.dat, data 12->47 dropped 69 Detected Remcos RAT 12->69 71 Tries to harvest and steal browser information (history, passwords, etc) 12->71 73 Installs a global keyboard hook 12->73 23 RFQ# RE-7.1210594.exe 12->23         started        25 Conhost.exe 17->25         started        27 Conhost.exe 19->27         started        29 Conhost.exe 21->29         started        31 Conhost.exe 21->31         started        33 Conhost.exe 21->33         started        35 59 other processes 21->35 file9 signatures10 process11
Gathering data
Threat name:
Win32.Trojan.Guloader
Status:
Suspicious
First seen:
2026-05-21 02:37:41 UTC
File Type:
PE (Exe)
Extracted files:
17
AV detection:
16 of 37 (43.24%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection discovery installer rat spyware stealer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Accesses Microsoft Outlook profiles
Checks installed software on the system
Contacts third-party web service commonly abused for C2
Loads dropped DLL
Reads user/profile data of web browsers
Family: Remcos
Malware Config
C2 Extraction:
204.10.160.191:2404
Unpacked files
SH256 hash:
c9624e6bd4e2336c04ac9a5ccbb67a5f66312528fa839547e4a543f12aa46ad5
MD5 hash:
86666c4287b523e0b80c14dbda780f08
SHA1 hash:
9e3b5d55d1d97611ba8fca903eb8bddf8a9b0810
SH256 hash:
7229e483771d3b833e68ac582c99a57dfaef7e6aa7aacc5faedacaf2d9d203b0
MD5 hash:
6ba011498156f594d1345fa85831d120
SHA1 hash:
7dfc87657ea941d2b8bc2965d5861cdedac1ee7b
SH256 hash:
7ad58b81fe94a9d2e27d7ce91162bfda242f1a991fce53c66bbe861565d74036
MD5 hash:
9395adf541cb829fd992189c368fc924
SHA1 hash:
641721e049b7499caa3f0caf747ebd28a1196f95
SH256 hash:
7853be9190489ba84dae8232e9a967cec02d941732cb4137bc9ae6a392e89fb8
MD5 hash:
3fbd78c889fa40a2e5567b980c57b7db
SHA1 hash:
303564bfa6fd5ab7a65d35ae1cd14a05643b6b5d
SH256 hash:
e20666c498941d36bfd0eae411ad73c475d043cee39b50c31734a70eecaae0bb
MD5 hash:
13bd8e89dc79004d85ab02626e08c3c5
SHA1 hash:
0ef0efb3237233de26f55c4420753ed0fed418ad
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Ins_NSIS_Buer_Nov_2020_1
Author:Arkbird_SOLG
Description:Detect NSIS installer used for Buer loader
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

GuLoader

Executable exe c9624e6bd4e2336c04ac9a5ccbb67a5f66312528fa839547e4a543f12aa46ad5

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments