MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f1c3cf63de4ed1f73666aef9032ac58d0fe4af4cb6195028e98cbe95cc6c1d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3f1c3cf63de4ed1f73666aef9032ac58d0fe4af4cb6195028e98cbe95cc6c1d3
SHA3-384 hash: a7a772f21ecbd1e1bf5687ae34299e4629f37cc1c5430babe6d9963685af7db340a1599f66d4203af8609b9920edb3a8
SHA1 hash: 296dcd44ee5fe40e746c705a5b83022b98b407d5
MD5 hash: 0a35ea7e75d8e14029c763b4e80afc6d
humanhash: seven-single-pasta-romeo
File name:dfg90erhj34h0g0dfg0cvcv00340sfsdf84fdcv9bv0cv03dfiu3200fdsf23sdfvb90cvb90030gdfg0cvb09c0b0.hta
Download: download sample
Signature RemcosRAT
File size:196'420 bytes
First seen:2025-10-22 17:30:29 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:text/html
ssdeep 6:q43taxtWKe6mEZbLjksmFWZT32g+V1X64mEF29chLYOoeMw5MWXfGu:Tgx0KhbLjvl29DrF2ILqeMx8Gu
TLSH T1741426233D265EA680321BB685FDA87CA1A64611528E2B32359D08077F45A575C8258F
Magika html
Reporter abuse_ch
Tags:hta RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Clean
File Type:
hta
First seen:
2025-10-22T14:55:00Z UTC
Last seen:
2025-10-22T15:14:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Verdict:
inconclusive
YARA:
2 match(es)
Tags:
Html
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-10-22 17:37:54 UTC
File Type:
Text (HTML)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

HTML Application (hta) hta 3f1c3cf63de4ed1f73666aef9032ac58d0fe4af4cb6195028e98cbe95cc6c1d3

(this sample)

  
Delivery method
Distributed via web download

Comments