🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 200ff75f2ffd6488ac25ac5cdb4552a1d2dc321f36a398e3d648e9531769b93e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 200ff75f2ffd6488ac25ac5cdb4552a1d2dc321f36a398e3d648e9531769b93e
SHA3-384 hash: b80aaa4b633b2870c3b5bd186b52b15842a5c15c21aeebf9ae664a13e77d83f6523c99d6796e60d990b9ddb5dd42fa3d
SHA1 hash: 85a767adcc2bcbda4236148889271105a45a8aa4
MD5 hash: a0fc1d4d47153bc202b0bf581267f53b
humanhash: river-berlin-sodium-texas
File name:SecuriteInfo.com.X97M.DownLoader.2343.279.1004
Download: download sample
Signature RemcosRAT
File size:795'648 bytes
First seen:2026-09-10 06:21:44 UTC
Last seen:2026-09-10 07:25:19 UTC
File type:Excel file xlsx
MIME type:application/vnd.ms-excel
ssdeep 12288:2UyIOrEuY8GkUlDRsJ47/ps0GzldCtri711OS2xkVczSWMwmXVildfPNXm:yIO4uY+2DRY4YWi711OS6kV9ildfPNX
TLSH T197052311EBD0BBEBD1666470471E8659E88ECE3EEF92B0876314745E78733F26382458
TrID 47.4% (.XLS) Microsoft Excel sheet (32500/1/3)
40.8% (.XLS) Microsoft Excel sheet (alternate) (28000/1/3)
11.6% (.) Generic OLE2 / Multistream Compound (8000/1)
Magika xls
Reporter SecuriteInfoCom
Tags:RemcosRAT xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Application name is Microsoft Excel
File Format is MS Excel 97-2003
Container Format is OLE
Office document is in encrypted
OLE dump

MalwareBazaar was able to identify 7 sections in this file using oledump:

Section IDSection sizeSection name
1114 bytesCompObj
2244 bytesDocumentSummaryInformation
3200 bytesSummaryInformation
4776 bytesMBD002557E3/Ole
5114 bytesMBD00263149/CompObj
6502029 bytesMBD00263149/Package
7281716 bytesWorkbook

Intelligence


File Origin
# of uploads :
2
# of downloads :
108
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
xlsx
Verdict:
No threats detected
Analysis date:
2026-09-10 06:42:25 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Creating a window
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Launching a process
Possible injection to a system process
Connection attempt by exploiting the app vulnerability
Sending an HTTP GET request
Bypassing of proactive protection methods using Windows Management Instrumentation (WMI)
Sending a custom TCP request by exploiting the app vulnerability
Launching a process by exploiting the app vulnerability
Result
Verdict:
Malicious
File Type:
Legacy Excel File
Behaviour
SuspiciousRTF detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
CVE-2017-0199 downloader evasive exploit macros
Label:
Benign
Suspicious Score:
3/10
Score Malicious:
3%
Score Benign:
97%
Verdict:
Malicious
File Type:
xls
First seen:
2026-09-09T23:57:00Z UTC
Last seen:
2026-09-10T03:10:00Z UTC
Hits:
~1000
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Office Document
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence ransomware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Suspicious behavior: AddClipboardFormatListener
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Uses Volume Shadow Copy WMI provider
Uses Volume Shadow Copy service COM API
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments