Beware of phishing emails disguised as quote requests
Recently, the AhnLab SEcurity intelligence Center (ASEC) confirmed that phishing emails disguised as requests for project quotes are being circulated. The email body is disguised as a request to submit a quote for discussing the project budget and prompts recipients to download an attached compressed file for verification.

[Figure 1] Phishing email body
When a user downloads and decompresses the attached compressed file, a VBScript file is hidden inside, as shown in [Figure 2]. This VBScript first checks for the presence of the legitimate system file notepad.Exe, then extracts the characters ‘s’ and ‘l’ from the file’s hexadecimal data. The extracted characters are used to construct the final executable file name, “powershell,” which is an obfuscation technique designed to make analysis and detection more difficult. The PowerShell script that runs afterward restores the obfuscated code by replacing arbitrary tokens with actual characters and symbols. The identified key substitution rules are as follows.
| Obfuscation Tokens | Substitution Character |
|---|---|
| Axis | S |
| Longar | O |
| Hoimulz | $ |
| Humoled | C |
[Table 1] Substitution Rules
In this way, the threat actor repeatedly performs token-based string substitution to reconstruct the original PowerShell Command and then executes malicious behavior.

[Figure 2] RAR compressed file

[Figure 3] PowerShell.Exe string generation

[Figure 4] Excerpt from VBScript-2
The executed PowerShell script decodes the obfuscated string inside it in the manner shown in [Figure 5], and then executes the reconstructed command.

[Figure 5] String decryption method
It then connects to the threat actor’s C2 server to download an additional payload; the downloaded data is organized into three sections based on offsets, as shown in [Table 2] and [Figure 7].
Additional Payload Download C2
- Hxxp://drive.Google[.]Com/uc?Export=download&id=1ge2-tdX0-_A6ZU6FDMEFynhz1m0L5lHm

[Figure 6] Additional Payload Download
| Offset Range | Components | Size |
|---|---|---|
| 0X00000–0x01C98 | Loader | 7,321 Bytes |
| 0X01C99–0x2267F | Payload | 133,607 Bytes |
| 0X22680–0x2714D | Secondary PowerShell payload | 19,150 Bytes |
[Table 2] Additional Payload Components

[Figure 7] Additional Payload Structure
The downloaded payload is stored in the %APPDATA%\Maleic.For Path, and among the three sections, the secondary PowerShell payload is the first to execute in memory. Subsequently, this script initiates the execution of the loader and payload.

[Figure 8] Execution of the Secondary PowerShell Payload
The executed secondary PowerShell payload creates a ShellWindows COM object to bypass UAC. It then indirectly uses the ShellExecute Path of explorer.Exe to launch a new PowerShell process and execute subsequent commands with privilege escalation.
ShellWindows CLSID
- {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

[Figure 9] UAC Bypass
After privilege escalation, the loader section is extracted from the %APPDATA%\Maleic.For file and loaded into memory. At this point, the Payload section is passed as an argument to the loader; the loader decrypts it using an XOR operation and executes it in memory.

[Figure 10] Execution of the Loader Section

[Figure 11] Payload Decryption and Execution
The decrypted and executed payload downloads Remcos RAT—the final piece of malware—from the C2 server into memory. It then decrypts this and injects it into the legitimate process MicrosoftEdgeUpdate.Exe to execute it.
Remcos RAT Download C2
- Hxxp://drive.Google[.]Com/uc?Export=download&id=1yJZysgMU6LZmCZtpko0y1uO1jsbYDIRO

[Figure 12] To download and execute the final malware
The Remcos RAT, once executed, is malware that receives and executes remote commands on the infected system. It collects system and user information through various functions, such as keylogging, screen capture, and file manipulation. The collected information and execution results are transmitted externally via communication with the C2 server.
Remcos RAT C2
- 102.220.160[.]104:2404

[Figure 13] Remcos RAT in final execution
Response Guide
1. Verify the Sender
- Verify that the sender’s email address belongs to an official domain.
2. Check Hyperlinks and Attachments
- If the email prompts you to click on an image attached to the body of the message, check the linked URL first before clicking. Suspicious URLs often redirect to legitimate pages via intermediate paths rather than going directly to the official page, so examine them carefully. Additionally, if there are attachments, check for suspicious file extensions (.Exe, .Vbs, .Js, etc.).
3. Be Cautious When Entering Sensitive Information
- If you are asked to provide sensitive information, such as login credentials, always verify that the page’s URL corresponds to the official website before entering any information. If the page is not official, it is highly likely that the URL is suspicious, so caution is required. In particular, check the page’s security certification (HTTPS, padlock icon) before entering sensitive information, and never enter any information if you have any doubts.