🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bfd0b95c3baf8b621e009aec5b92344e4e236ebc12b34fad891d0a1996668c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 4bfd0b95c3baf8b621e009aec5b92344e4e236ebc12b34fad891d0a1996668c6
SHA3-384 hash: ec0d2b30a1b1d79cfb105c56ebb9b12c040b0d7594832eaeb89f5d983f7b40e2b6de2db10d4d5ccfba58f1c64e72e55c
SHA1 hash: 6bc806dbf2dcb6106ff68a42507896b78d695366
MD5 hash: f21f06fadc67c3573216fdc5a88a2864
humanhash: carbon-louisiana-zulu-jersey
File name:Inv HTQ 2.4.0098.26.rar
Download: download sample
Signature RemcosRAT
File size:383'209 bytes
First seen:2026-04-16 10:16:14 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:+0VqTkHAG9BpO7m3VgqR3uYn9VAJ4JZKbJ5iBj+klv7PjiOjsXxwYf1oSOFx9rzb:BVqTkHdFJuYn9VASEHiR+gjjcwSoNVr/
TLSH T1BA8423DC940BF4DC6F84EEE6875466790E7FAF11A8488B2D755EF3412A9A91A3870CC0
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter ilyasmini
Tags:rar RAT remcos RemcosRAT stealer


Avatar
ilyasrifai_
very nasty

Intelligence


File Origin
# of uploads :
1
# of downloads :
135
Origin country :
ID ID
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Inv HTQ 2.4.0098.26.exe
File size:736'528 bytes
SHA256 hash: cae9e6bcef35b5cc7f9958e342fbfea23fe231ccb33f7951eb6eb09ab4d036af
MD5 hash: 4f598605dcb2960e9672f2600f6d4a6f
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
91.7%
Tags:
injection obfusc blic
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
adaptive-context anti-debug installer installer installer-heuristic microsoft_visual_cc nsis signed soft-404
Verdict:
Malicious
File Type:
rar
First seen:
2026-04-15T22:59:00Z UTC
Last seen:
2026-04-16T13:27:00Z UTC
Hits:
~10
Gathering data
Threat name:
Win32.Trojan.Makoob
Status:
Malicious
First seen:
2026-04-16 10:17:15 UTC
File Type:
Binary (Archive)
Extracted files:
8
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost discovery installer persistence rat spyware stealer
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
NSIS installer
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Drops file in Program Files directory
Drops file in Windows directory
Drops file in System32 directory
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Adds Run key to start application
Checks installed software on the system
Contacts third-party web service commonly abused for C2
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Reads user/profile data of web browsers
Family: Remcos
Malware Config
C2 Extraction:
198.46.173.5:3000
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

rar 4bfd0b95c3baf8b621e009aec5b92344e4e236ebc12b34fad891d0a1996668c6

(this sample)

Comments