MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 14


Intelligence 14 IOCs YARA 13 File information Comments

SHA256 hash: 0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225
SHA3-384 hash: 45ee391fc6592a0f68dfd67b145cbb28755ea08854ab876fd019dbf4d008c4ac81e7c0de552a023dc5ad30e7ba3010f3
SHA1 hash: 37e1c520d9d6359582f566e2c8339d6a2a66e546
MD5 hash: 34c53b495cd8216306cd4dff6986077c
humanhash: april-jersey-double-carbon
File name:Setup.exe
Download: download sample
Signature RemusStealer
File size:15'677'870 bytes
First seen:2026-08-25 20:18:21 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (80 x RemusStealer, 5 x ValleyRAT, 5 x SalatStealer)
ssdeep 393216:Kv/g4W6G87mIyAgEUa407aO200tJ47Id3Oivcy1mPZeLd:KNWh2yJEUrnI0n47qOq1eId
TLSH T137F6330AA7A034E8E516D9788946CB02E7727C8A9F70CE1F17D4FA673F62050E92D735
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (914 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter aachum
Tags:ClickFraud exe gcleaner RemusStealer sfx unluckytool-com


Avatar
iamaachum
https://winds11.site/aa/Setup.rar

RemusStealer C2:
http://goldeth.click :6572/users
http://kupzovo.shop:7567/users
http://vexdico.shop:8539/messages
GCleaner C2:
91.92.242.236

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
ES ES
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Creating a process from a recently created file
Creating a process with a hidden window
Using the Windows Management Instrumentation requests
Creating a file in the %temp% subdirectories
Launching a process
Deleting a recently created file
DNS request
Connection attempt
Changing a file
Unauthorized injection to a recently created process
Query of malicious DNS domain
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug cmd fingerprint golang installer installer installer-heuristic large-file lolbin microsoft_visual_cc msbuild obfuscated overlay packed powershell reconnaissance sfx
Result
Threat name:
Amadey, GCleaner, REMUS Stealer, Socks5S
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
AI detected malicious page (phishing or scam)
Allocates memory in foreign processes
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Changes security center settings (notifications, updates, antivirus, firewall)
Detected unpacking (changes PE section rights)
Detected unpacking (creates a PE file in dynamic memory)
Detected unpacking (overwrites its own PE header)
Drops large PE files
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious webpage
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes / dynamic malware analysis system (registry check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses known network protocols on non-standard ports
Uses the Windows Restart Manager Abuse for Browser Credential File unlocking
Verifies if a H.264 Video Encoder exists (likely to detect the VM)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected Amadey
Yara detected Amadeys Clipper DLL
Yara detected AntiVM3
Yara detected GCleaner
Yara detected REMUS Stealer
Yara detected Socks5Systemz
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963653 Sample: Setup.exe Startdate: 25/08/2026 Architecture: WINDOWS Score: 100 132 config.ridgecanvas.xyz 2->132 134 45.91.200.135 PODAONLV Netherlands 2->134 136 24 other IPs or domains 2->136 170 Suricata IDS alerts for network traffic 2->170 172 Found malware configuration 2->172 174 Malicious sample detected (through community Yara rule) 2->174 178 22 other signatures 2->178 12 Setup.exe 3 9 2->12         started        16 svchost.exe 2->16         started        18 svchost.exe 2->18         started        21 9 other processes 2->21 signatures3 176 Performs DNS queries to domains with low reputation 132->176 process4 dnsIp5 126 C:\Users\user\Desktop\appFile.exe, PE32+ 12->126 dropped 128 C:\Users\user\Desktop\ae_mixtwo.exe, PE32 12->128 dropped 130 C:\Users\user\Desktop\OpenLink.ps1, ASCII 12->130 dropped 248 Drops large PE files 12->248 23 ae_mixtwo.exe 10 12->23         started        27 appFile.exe 12->27         started        29 wscript.exe 12->29         started        250 Changes security center settings (notifications, updates, antivirus, firewall) 16->250 31 MpCmdRun.exe 16->31         started        138 127.0.0.1 unknown unknown 18->138 33 conhost.exe 21->33         started        35 conhost.exe 21->35         started        file6 signatures7 process8 file9 122 C:\Users\user\AppData\Local\Temp\...\re21.exe, PE32+ 23->122 dropped 224 Multi AV Scanner detection for dropped file 23->224 226 Writes to foreign memory regions 23->226 228 Allocates memory in foreign processes 23->228 230 Injects a PE file into a foreign processes 23->230 37 MSBuild.exe 33 23->37         started        42 re21.exe 3 23->42         started        232 Detected unpacking (creates a PE file in dynamic memory) 27->232 234 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 27->234 236 Tries to steal Mail credentials (via file / registry access) 27->236 244 7 other signatures 27->244 238 Suspicious powershell command line found 29->238 240 Wscript starts Powershell (via cmd or directly) 29->240 242 Bypasses PowerShell execution policy 29->242 246 3 other signatures 29->246 44 powershell.exe 29->44         started        46 conhost.exe 31->46         started        signatures10 process11 dnsIp12 154 91.92.242.236, 49713, 80 OMEGATECH-ASSC Netherlands 37->154 156 drive.usercontent.google.com 142.250.217.225, 443, 49711 GOOGLE-GoogleLLCUS United States 37->156 114 C:\Users\user\AppData\...\uQ1XfeLlH8.exe, PE32 37->114 dropped 116 C:\Users\user\AppData\...\eIwb6Jr8sVT.exe, PE32+ 37->116 dropped 118 C:\Users\user\AppData\...\RsKzAiMg5xQ7U.exe, PE32 37->118 dropped 120 7 other malicious files 37->120 dropped 214 Unusual module load detection (module proxying) 37->214 48 RsKzAiMg5xQ7U.exe 37->48         started        51 HB7jMQYAiS.exe 37->51         started        55 SNrLE8Ks0qR.exe 37->55         started        63 5 other processes 37->63 216 Multi AV Scanner detection for dropped file 42->216 218 Writes to foreign memory regions 42->218 220 Modifies the context of a thread in another process (thread injection) 42->220 222 Injects a PE file into a foreign processes 42->222 57 MSBuild.exe 42->57         started        59 chrome.exe 44->59         started        61 conhost.exe 44->61         started        file13 signatures14 process15 dnsIp16 94 C:\Users\user\AppData\...\RsKzAiMg5xQ7U.tmp, PE32 48->94 dropped 65 RsKzAiMg5xQ7U.tmp 48->65         started        140 config.ridgecanvas.xyz 172.67.157.155 CLOUDFLARENET-CloudflareIncUS Canada 51->140 180 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 51->180 182 Found many strings related to Crypto-Wallets (likely being stolen) 51->182 184 Tries to detect virtualization through RDTSC time measurements 51->184 204 5 other signatures 51->204 68 HB7jMQYAiS.exe 51->68         started        71 HB7jMQYAiS.exe 51->71         started        142 jij.sm188dvlv.icu 104.21.62.229 CLOUDFLARENET-CloudflareIncUS Canada 55->142 144 dev.epicgames.com.cdn.cloudflare.net 104.18.0.68 CLOUDFLARENET-CloudflareIncUS Canada 55->144 186 Multi AV Scanner detection for dropped file 55->186 188 Tries to harvest and steal browser information (history, passwords, etc) 55->188 190 Uses the Windows Restart Manager Abuse for Browser Credential File unlocking 55->190 82 2 other processes 55->82 146 vexdico.shop 165.227.199.109, 49735, 8539 DIGITALOCEAN-ASN-DigitalOceanLLCUS United States 57->146 192 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 57->192 194 Unusual module load detection (module proxying) 57->194 148 192.168.2.4, 443, 49706, 49707 unknown unknown 59->148 150 192.168.2.6 unknown unknown 59->150 152 192.168.2.9 unknown unknown 59->152 73 chrome.exe 59->73         started        96 C:\Users\user\AppData\...\D6RTJ1nH0x.tmp, PE32 63->96 dropped 98 C:\Users\user\AppData\...\uQ1XfeLlH8.exe.log, ASCII 63->98 dropped 196 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 63->196 198 Writes to foreign memory regions 63->198 200 Allocates memory in foreign processes 63->200 202 Injects a PE file into a foreign processes 63->202 76 D6RTJ1nH0x.tmp 63->76         started        78 MSBuild.exe 63->78         started        80 conhost.exe 63->80         started        84 2 other processes 63->84 file17 signatures18 process19 dnsIp20 100 C:\Users\user\AppData\Local\...\_shfoldr.dll, PE32 65->100 dropped 102 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 65->102 dropped 104 C:\Users\user\AppData\Local\...\_iscrypt.dll, PE32 65->104 dropped 112 21 other malicious files 65->112 dropped 86 AdvDefragConsole.exe 65->86         started        206 Tries to harvest and steal browser information (history, passwords, etc) 68->206 208 Found direct / indirect Syscall (likely to bypass EDR) 68->208 210 Tries to detect sandboxes / dynamic malware analysis system (registry check) 68->210 164 pulse.quantumbytehub1.lol 104.21.57.57, 443, 49723, 49724 CLOUDFLARENET-CloudflareIncUS Canada 73->164 166 www.google.com 142.251.150.119, 443, 49716, 49720 GOOGLE-GoogleLLCUS United States 73->166 168 5 other IPs or domains 73->168 106 Chrome Cache Entry: 261, PDP-11 73->106 dropped 108 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 76->108 dropped 212 Queries sensitive service information (via WMI, Win32_LogicalDisk, often done to detect sandboxes) 76->212 110 C:\Users\user\AppData\Local\...\Bwale.exe, PE32 78->110 dropped 90 Bwale.exe 78->90         started        file21 signatures22 process23 dnsIp24 158 94.26.38.17 OMEGATECH-ASSC Netherlands 86->158 160 196.251.121.77 Hero-TelecomsZA Turkey 86->160 162 2 other IPs or domains 86->162 124 C:\ProgramData\...\AdvDefragConsole.exe, PE32 86->124 dropped 92 conhost.exe 90->92         started        file25 process26
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.20 SOS: 0.21 SOS: 0.92 Win 64 Exe x64
Threat name:
ByteCode-MSIL.Trojan.Injectornett
Status:
Malicious
First seen:
2026-08-25 20:19:13 UTC
File Type:
PE+ (Exe)
Extracted files:
62
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:gcleaner family:remus_stealer discovery execution loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Family: GCleaner
Family: Remus
Malware Config
C2 Extraction:
http://goldeth .click :6572/users
http://kupzovo.shop:7567/users
http://vexdico.shop:8539/messages
185.156.73.98
45.91.200.135
Dropper Extraction:
https://wappingerbicornshaps.com/s4r7aa2f7f74b7ac2ab0af7589004c3a8ef07971edb98
Unpacked files
SH256 hash:
0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225
MD5 hash:
34c53b495cd8216306cd4dff6986077c
SHA1 hash:
37e1c520d9d6359582f566e2c8339d6a2a66e546
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemusStealer

Executable exe 0beaf7839d3a1b2e0c86566fd597c159da9f154e2be236d482ecb2c9ff32e225

(this sample)

  
Delivery method
Distributed via web download

Comments