🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4902684357fbd82d08c155eac5ea598fcda0446f408294fd8a18085d7ad1ac73. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 12


Intelligence 12 IOCs 1 YARA 32 File information Comments

SHA256 hash: 4902684357fbd82d08c155eac5ea598fcda0446f408294fd8a18085d7ad1ac73
SHA3-384 hash: 2f414115e8d1c0291576fece197e2ba7c22adf50c0c6e0f39ae19362a8ddb2a029cf456f18fcbec5ac9ff78313a5697f
SHA1 hash: d1f36ea80e20f9d6435c3975a2f59cc4c4d6e626
MD5 hash: 0112f1cffd646ed0818c3088ab50ae8f
humanhash: echo-mobile-victor-princess
File name:0112f1cffd646ed0818c3088ab50ae8f.exe
Download: download sample
Signature RemusStealer
File size:44'169'216 bytes
First seen:2026-10-07 15:50:14 UTC
Last seen:Never
File type:Executable exe
MIME type:application/vnd.microsoft.portable-executable
imphash 3e3c7cd3783c316bb26868db037273eb (2 x RemusStealer)
ssdeep 786432:9Ykga3uUOqT4eKdeSvMYEj9+xDnWoOA6ef9C2MDNXDD2RpZW7hbOaKlLVeZ:9YkmUOw4eKdHvojcRPOA6CUD8RrGODS
TLSH T1D7A7333AD3C0D961EC263936CB345215F5F55E128FC8902A9378EF9AB53FC899E18790
TrID 37.0% (.EXE) Win64 Executable (generic) (6522/11/2)
28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
11.5% (.EXE) OS/2 Executable (generic) (2029/13)
11.3% (.EXE) Generic Win/DOS Executable (2002/3)
11.3% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
dhash icon 0e334d695171338e (1 x RemusStealer)
Reporter abuse_ch
Tags:exe RemusStealer


Avatar
abuse_ch
RemusStealer C2:
15.204.253.8:5621

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
15.204.253.8:5621 https://threatfox.abuse.ch/ioc/1956223/

Intelligence


File Origin
# of uploads :
1
# of downloads :
190
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-10-07 16:05:10 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% directory
Creating a process from a recently created file
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Сreating synchronization primitives
Creating a file in the %AppData% subdirectories
Creating a file
Creating a process with a hidden window
Searching for synchronization primitives
Creating a window
DNS request
Launching a process
Connection attempt
Sending an HTTP GET request
Using the Windows Management Instrumentation requests
Reading critical registry keys
Running batch commands
Changing a file
Launching the process to change network settings
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Stealing user critical data
Enabling autorun by creating a file
Unauthorized injection to a system process
Sending an HTTP POST request to an infection source
Sending an HTTP GET request to an infection source
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-debug krypt microsoft_visual_cc packed reconnaissance
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-09-26T20:16:00Z UTC
Last seen:
2026-10-05T08:43:00Z UTC
Hits:
~100
Result
Threat name:
SolarisLoader, Stealc v2, SvcStealer
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Antivirus detection for dropped file
C2 URLs / IPs found in malware configuration
Changes memory attributes in foreign processes to executable or writable
Changes the view of files in windows explorer (hidden files and folders)
Contains functionality to inject threads in other processes
Creates a thread in another existing process (thread injection)
Creates multiple autostart registry keys
Deletes itself after installation
Early bird code injection technique detected
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Injects code into the Windows Explorer (explorer.exe)
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Queries Google from non browser process on port 80
Queues an APC in another process (thread injection)
Sample uses process hollowing technique
Sample uses string decryption to hide its real strings
Sets debug register (to hijack the execution of another thread)
Sigma detected: Files With System Process Name In Unsuspected Locations
Suricata IDS alerts for network traffic
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected SolarisLoader
Yara detected Stealc v2
Yara detected SvcStealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1983670 Sample: 5isdg59aCd.exe Startdate: 07/10/2026 Architecture: WINDOWS Score: 100 142 www.google.com 2->142 144 td3o6vaa2uch4xycu3vyf37pbpu1ze26sbgajia.com 2->144 146 2 other IPs or domains 2->146 178 Suricata IDS alerts for network traffic 2->178 180 Found malware configuration 2->180 182 Malicious sample detected (through community Yara rule) 2->182 184 9 other signatures 2->184 10 5isdg59aCd.exe 8 2->10         started        13 explorer.exe 2->13 injected 15 wlrmdr.exe 2->15         started        19 4 other processes 2->19 signatures3 process4 dnsIp5 128 C:\Users\user\Desktop128FTOKEN API v2.0.exe, PE32+ 10->128 dropped 130 C:\Users\user\AppData\Local\...\p1ljvdvr.exe, PE32+ 10->130 dropped 132 C:\Users\user\AppData\Local\...\dmsjrzf3.exe, PE32+ 10->132 dropped 136 4 other malicious files 10->136 dropped 21 8dr3azvn.exe 1 17 10->21         started        26 NFTOKEN API v2.0.exe 10->26         started        28 p1ljvdvr.exe 1 10->28         started        38 4 other processes 10->38 30 syshost.exe 13->30         started        32 syshost.exe 13->32         started        34 conhostpuw.exe 13->34         started        36 conhostpuw.exe 13->36         started        160 193.178.158.65 IPC-ASRU Russia 15->160 134 C:\Users\user\AppData\Local\...\k4axmjt8.exe, PE32+ 15->134 dropped 162 Multi AV Scanner detection for dropped file 15->162 164 Contains functionality to inject threads in other processes 15->164 166 Injects code into the Windows Explorer (explorer.exe) 15->166 174 3 other signatures 15->174 168 Changes memory attributes in foreign processes to executable or writable 19->168 170 Writes to foreign memory regions 19->170 172 Allocates memory in foreign processes 19->172 176 2 other signatures 19->176 file6 signatures7 process8 dnsIp9 148 www.google.com 142.251.150.119 GOOGLE-GoogleLLCUS United States 21->148 92 C:\Users\user\AppData\Roaming\...\wlrmdr.exe, PE32+ 21->92 dropped 94 C:\Users\user\AppData\Local\...\umclwfba.exe, PE32+ 21->94 dropped 96 C:\Users\user\AppData\Local\...\i73behd4.exe, PE32+ 21->96 dropped 106 6 other malicious files 21->106 dropped 188 Antivirus detection for dropped file 21->188 190 Multi AV Scanner detection for dropped file 21->190 192 Changes the view of files in windows explorer (hidden files and folders) 21->192 210 2 other signatures 21->210 40 umclwfba.exe 21->40         started        44 fsugnpy9.exe 21->44         started        47 grxna9mt.exe 21->47         started        59 3 other processes 21->59 108 44 other malicious files 26->108 dropped 49 NFTOKEN API v2.0.exe 26->49         started        98 C:\Users\user\AppData\Roaming\synchost.exe, PE32+ 28->98 dropped 51 synchost.exe 75 28->51         started        194 Injects code into the Windows Explorer (explorer.exe) 30->194 196 Writes to foreign memory regions 30->196 198 Allocates memory in foreign processes 30->198 200 Creates a thread in another existing process (thread injection) 32->200 202 Injects a PE file into a foreign processes 32->202 100 C:\Users\user\AppData\Roaming\syshost.exe, PE32+ 38->100 dropped 102 C:\Users\user\AppData\...\conhostpuw.exe, PE32+ 38->102 dropped 104 C:\Users\user\AppData\Local\...\1v6foszb.tmp, PE32 38->104 dropped 204 Found many strings related to Crypto-Wallets (likely being stolen) 38->204 206 Creates multiple autostart registry keys 38->206 208 Contains functionality to inject threads in other processes 38->208 212 3 other signatures 38->212 53 HelpPane.exe 32 38->53         started        55 syshost.exe 38->55         started        57 1v6foszb.tmp 38->57         started        file10 signatures11 process12 dnsIp13 110 C:\Users\user\...\SystemServiceManager.exe, PE32+ 40->110 dropped 214 Changes memory attributes in foreign processes to executable or writable 40->214 216 Uses schtasks.exe or at.exe to add and modify task schedules 40->216 234 3 other signatures 40->234 61 schtasks.exe 40->61         started        150 109.238.86.106 PIONEERNETRU United Kingdom 44->150 218 Early bird code injection technique detected 44->218 220 Found many strings related to Crypto-Wallets (likely being stolen) 44->220 236 2 other signatures 44->236 63 chrome.exe 44->63         started        112 C:\Users\user\Desktop\5isdg59aCd.exe.tmp~, PE32+ 47->112 dropped 114 C:\Users\user\Desktop\5isdg59aCd.exe (copy), PE32+ 47->114 dropped 222 Deletes itself after installation 47->222 152 ip-api.com 208.95.112.1 TUT-AS-TotalUptimeTechnologiesLLCUS United States 49->152 65 cmd.exe 49->65         started        154 193.178.158.107, 49722, 49726, 49728 IPC-ASRU Russia 51->154 156 196.251.107.186, 49721, 49724, 49727 FEMOITGB Germany 51->156 158 193.178.158.57 IPC-ASRU Russia 51->158 116 C:\Users\...\6107cbb0a359ada5_pyinfector.exe, PE32+ 51->116 dropped 124 5 other malicious files 51->124 dropped 224 Multi AV Scanner detection for dropped file 51->224 226 Queries DNS domain through GetComputerNameExW (potential sandbox evasion) 51->226 67 bc116af5e724cfa4_zx.exe 51->67         started        71 91ee2c4a395d400d_Persevering_5802.exe 51->71         started        126 2 other malicious files 53->126 dropped 228 Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc) 53->228 230 Tries to harvest and steal browser information (history, passwords, etc) 53->230 238 4 other signatures 53->238 232 Contains functionality to inject threads in other processes 55->232 118 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 57->118 dropped 120 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 57->120 dropped 122 C:\Users\user\AppData\Local\...\639ahbul.tmp, PE32 59->122 dropped file14 signatures15 process16 file17 73 conhost.exe 61->73         started        75 conhost.exe 65->75         started        82 C:\Users\user\AppData\...\unicodedata.pyd, PE32+ 67->82 dropped 84 C:\Users\user\AppData\Local\...\select.pyd, PE32+ 67->84 dropped 86 C:\Users\user\AppData\Local\...\python313.dll, PE32+ 67->86 dropped 90 9 other malicious files 67->90 dropped 186 Multi AV Scanner detection for dropped file 67->186 77 bc116af5e724cfa4_zx.exe 67->77         started        88 C:\...\91ee2c4a395d400d_Persevering_5802.tmp, PE32 71->88 dropped 79 91ee2c4a395d400d_Persevering_5802.tmp 71->79         started        signatures18 process19 file20 138 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 79->138 dropped 140 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 79->140 dropped
Gathering data
Threat name:
Win64.Dropper.Yogi
Status:
Malicious
First seen:
2026-09-27 00:55:39 UTC
File Type:
PE+ (Exe)
Extracted files:
2
AV detection:
19 of 36 (52.78%)
Threat level:
  3/5
Result
Malware family:
svcstealer
Score:
  10/10
Tags:
family:solaris_loader family:svcstealer defense_evasion discovery downloader execution installer loader persistence privilege_escalation pyinstaller stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of UnmapMainImage
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Inno Setup is an open-source installation builder for Windows applications.
Browser Information Discovery
Detects Pyinstaller
Enumerates physical storage devices
Event Triggered Execution: Netsh Helper DLL
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
System Location Discovery: System Language Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Adds Run key to start application
Enumerates connected drives
Looks up external IP address via web service
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Downloads MZ/PE file
Detects SvcStealer Payload
Family: SolarisLoader
Family: SvcStealer, Diamotrix
Malware Config
C2 Extraction:
193.178.158.107
193.178.158.65
196.251.107.186
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Glasses
Author:Seth Hardy
Description:Glasses family
Rule name:GlassesCode
Author:Seth Hardy
Description:Glasses code features
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:grakate_stealer_nov_2021
Rule name:INDICATOR_SUSPICIOUS_Binary_Embedded_Crypto_Wallet_Browser_Extension_IDs
Author:ditekSHen
Description:Detect binaries embedding considerable number of cryptocurrency wallet browser extension IDs.
Rule name:INDICATOR_SUSPICIOUS_Binary_Embedded_MFA_Browser_Extension_IDs
Author:ditekSHen
Description:Detect binaries embedding considerable number of MFA browser extension IDs.
Rule name:INDICATOR_SUSPICIOUS_Binary_References_Browsers
Author:ditekSHen
Description:Detects binaries (Windows and macOS) referencing many web browsers. Observed in information stealers.
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_SQLQuery_ConfidentialDataStore
Author:ditekSHen
Description:Detects executables containing SQL queries to confidential data stores. Observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_GENInfoStealer
Author:ditekSHen
Description:Detects executables containing common artifacts observed in infostealers
Rule name:INDICATOR_SUSPICIOUS_References_SecTools
Author:ditekSHen
Description:Detects executables referencing many IR and analysis tools
Rule name:Macos_Infostealer_Wallets_8e469ea0
Author:Elastic Security
Rule name:pe_detect_tls_callbacks
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:recordbreaker_win_generic
Author:_kphi
Rule name:SUSP_XORed_Mozilla_Oct19
Author:Florian Roth
Description:Detects suspicious single byte XORed keyword 'Mozilla/5.0' - it uses yara's XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.
Reference:https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force()
Rule name:SUSP_XORed_Mozilla_RID2DB4
Author:Florian Roth
Description:Detects suspicious XORed keyword - Mozilla/5.0
Reference:Internal Research
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:TigerRAT_pe_yaraify
Author:hunts-yara-code
Description:YARAify-tightened byte rule from 9 sample(s) -- VERIFY hits
Rule name:WIN_Malware_SalatStealer_ForgeAuto_542e717b
Author:Marjoriefort
Description:Detects SalatStealer (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_2ffc3572
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_5001c94c
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)
Rule name:WIN_Malware_Unknown_ForgeAuto_ce8c5b46
Author:Marjoriefort
Description:Detects Unknown (pe, etat binaire)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments