MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4839bf1dd907fc75d20582a25cf5aee9fc2009dda0a54fedaec40298848b60dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 4839bf1dd907fc75d20582a25cf5aee9fc2009dda0a54fedaec40298848b60dd
SHA3-384 hash: 54de52068e5d4b0c371bfc94ea105310e88be3e065bb009c67d9d18100fad51cae2bbe3ad45ad0552e8d50fd879989b6
SHA1 hash: 88a339c653b7061f95e783c5488d257eb98e1366
MD5 hash: eb207b4705ac6f285b2a76c0ffb732d7
humanhash: mars-bluebird-pip-fanta
File name:SHB89681.gz.zip
Download: download sample
Signature RemcosRAT
File size:44'008 bytes
First seen:2026-06-02 15:47:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 768:CxaID061a54slo9y5MUx5MiY1ST8Q6bp8298Xl4DwEzYQNaLLNGsLyQkZ:QaIDY54sl6pgMSgQ6CloFYQNaLLNZyQs
TLSH T11713F13A2CE6E850366ACD313088679CD6C049631A579BF61A22EC4E93E384971E537B
Magika zip
Reporter TomU
Tags:RemcosRAT zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:SHB89681.vbs
File size:86'399 bytes
SHA256 hash: 3da0d51f91991cea4662201e46fa87e7e9b7c74d4704fce249813b76ed48ed0f
MD5 hash: db9240b896496eff26650e092a8c0e1b
MIME type:text/plain
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
xtreme shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm fingerprint ping
Verdict:
Malicious
File Type:
zip
First seen:
2026-06-01T19:35:00Z UTC
Last seen:
2026-06-02T04:07:00Z UTC
Hits:
~10
Gathering data
Threat name:
Script-WScript.Trojan.Kepavll
Status:
Malicious
First seen:
2026-06-01 22:23:28 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Contacts third-party web service commonly abused for C2
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip 4839bf1dd907fc75d20582a25cf5aee9fc2009dda0a54fedaec40298848b60dd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments