🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0246919f4b9f7e52718b317fa01fc0cdc856e37f3d4770dff90d6febdea842f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 6 File information Comments

SHA256 hash: 0246919f4b9f7e52718b317fa01fc0cdc856e37f3d4770dff90d6febdea842f0
SHA3-384 hash: d0b65de943ef0d5201923eb47821de72ff475cf54d3fa56f5297d1531debf7c0d1d13b8b32f829f02d1abd8b82a1d21a
SHA1 hash: ef9600942fb6cc57aad22486d30d684f91d6b326
MD5 hash: bf6e9bfddef227dd69818457b4abc2ea
humanhash: potato-apart-sweet-purple
File name:scan.gz
Download: download sample
Signature RemcosRAT
File size:329'481 bytes
First seen:2025-12-03 09:40:32 UTC
Last seen:2026-05-20 17:17:23 UTC
File type: zip
MIME type:application/zip
ssdeep 6144:S4lmpinIHDBza6XvgXoNhoJ3G8NJbjEAU3sqFNmpMDnKI4wLHz7:SL+IHDBG6fKOQW6JEAU3JFA27rf
TLSH T1016423068308CA36D2D5333157C2F42AEE3EDA245796CD205E896B99F88F742E9D7172
Magika zip
Reporter cocaman
Tags:gz RemcosRAT Shipping zip


Avatar
cocaman
Malicious email (T1566.001)
From: ""COSCO SHIPPING Development Co., Ltd " <maci@vetempire.com>" (likely spoofed)
Received: "from faint.vetempire.com (faint.vetempire.com [94.26.68.177]) "
Date: "2 Dec 2025 18:27:21 -0800"
Subject: "Order Confirmation"
Attachment: "scan.gz"

Intelligence


File Origin
# of uploads :
3
# of downloads :
114
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:scan.exe
File size:356'648 bytes
SHA256 hash: 2efece12a2ddc0c550ad7606a0a965582e5bb2ac88bf01fab84ecd45c0c77d91
MD5 hash: cbca17f362f2c30d7c44c6450c3e055c
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
virus sage blic
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context anti-debug blackhole fingerprint installer installer installer-heuristic microsoft_visual_cc nsis overlay signed
Verdict:
Malicious
File Type:
zip
First seen:
2025-12-04T01:10:00Z UTC
Last seen:
2025-12-04T10:39:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-03 02:53:54 UTC
File Type:
Binary (Archive)
Extracted files:
20
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection discovery persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Adds Run key to start application
Legitimate hosting services abused for malware hosting/C2
Executes dropped EXE
Loads dropped DLL
Detected Nirsoft tools
NirSoft MailPassView
Remcos
Remcos family
Malware Config
C2 Extraction:
176.117.107.48:2404
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Detect_NSIS_Nullsoft_Installer
Author:Obscurity Labs LLC
Description:Detects NSIS installers by .ndata section + NSIS header string
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip 0246919f4b9f7e52718b317fa01fc0cdc856e37f3d4770dff90d6febdea842f0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments