MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3448f9c19e956d53f46bf3166707619e1b8516af8f800fac0f6b6987bc7961e0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 3448f9c19e956d53f46bf3166707619e1b8516af8f800fac0f6b6987bc7961e0
SHA3-384 hash: b559d8d0ba0e4cfbd070eab07786fb87d81d5917498ae64660da2cdaed225c30b156b50a32a25ca67cba1b37d2ee94d3
SHA1 hash: a6b60ca0b4ca660c5c6142fe57ac6cb44af0a1de
MD5 hash: 35de4e556cd85287e74b60c1ece9d678
humanhash: kilo-uncle-minnesota-solar
File name:goodthingsarecomingfromthebestplacescomingforme.hta
Download: download sample
Signature RemcosRAT
File size:14'133 bytes
First seen:2026-08-04 06:19:58 UTC
Last seen:2026-08-04 06:28:09 UTC
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 48:3fxtTHx2M0T1zoefRuuuuuuLMRkwK2VuuoXBuuuuxAxoExL1VPyTlDxlG:ptlMKe3Qvm3E
TLSH T160521E7E46D4FDDCA38B60ED40883A236445CD7BB05A0E1AB4CC9097B7A15BD1E3828D
Magika txt
Reporter abuse_ch
Tags:hta RemcosRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Verdict:
Malicious
File Type:
HTA File - Malicious
Payload URLs
URL
File name
http://217.154.188.255/35/eas/niceworking.vbe
HTA File
Behaviour
BlacklistAPI detected
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
powershell
Verdict:
Malicious
File Type:
html
First seen:
2026-07-27T08:00:00Z UTC
Last seen:
2026-07-30T19:43:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Encrypted powershell cmdline option found
Joe Sandbox ML detected suspicious sample
Multi AV Scanner detection for submitted file
PowerShell case anomaly found
Sigma detected: Potentially Suspicious PowerShell Child Processes
Sigma detected: Script Initiated Connection to Non-Local Network
Sigma detected: Suspicious Encoded PowerShell Command Line
Sigma detected: Suspicious MSHTA Child Process
Sigma detected: Suspicious PowerShell Parameter Substring
Sigma detected: WScript or CScript Dropper
System process connects to network (likely due to code injection or exploit)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Behaviour
Behavior Graph:
Verdict:
Malware
YARA:
3 match(es)
Tags:
DeObfuscated Html PowerShell T1027 T1059.001
Threat name:
Script-WScript.Dropper.Asthma
Status:
Malicious
First seen:
2026-07-28 04:10:34 UTC
AV detection:
9 of 38 (23.68%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

HTML Application (hta) hta 3448f9c19e956d53f46bf3166707619e1b8516af8f800fac0f6b6987bc7961e0

(this sample)

  
Delivery method
Distributed via web download

Comments