MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 698e43542e1d562ec451d4a9b7f05e45256492d33bde848e3804df428e14cd2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: 698e43542e1d562ec451d4a9b7f05e45256492d33bde848e3804df428e14cd2c
SHA3-384 hash: fa9ba8132c5c180562890c776784d07a8f473608dee4cab743daa50db1a3b951d25b8924f3c7031425907ae616014de0
SHA1 hash: 34a0520d8d32ff812309ccb6175ec454de05447c
MD5 hash: e9ba73003a85031f62a2720ba20e7170
humanhash: robin-purple-violet-ten
File name:SKM_C36826041510200.JS
Download: download sample
Signature RemcosRAT
File size:7'320'836 bytes
First seen:2026-04-17 14:13:54 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 196608:bLTPjNK6LsRjMDyFIT9Hd6v+MbSXZDpVNo3VRWPlU:bLT9sRjMDHJdXMb6ZDp/olz
TLSH T1EF768348E1787525A8EFC71CC07BD971484E646B394CEE5E303F822C2A51F63466A6EF
Magika txt
Reporter abuse_ch
Tags:js RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug autoit dropper evasive expired-cert fingerprint keylogger lolbin obfuscated persistence repaired schtasks
Verdict:
Malicious
File Type:
js
First seen:
2026-04-15T20:47:00Z UTC
Last seen:
2026-04-18T00:50:00Z UTC
Hits:
~100
Detections:
Trojan-Dropper.JS.SDrop.sb Trojan.JS.SAgent.sb HEUR:Trojan.Script.Generic HEUR:Trojan-Dropper.Script.Generic HEUR:Trojan-Downloader.Script.Generic
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
56 / 100
Signature
JavaScript source code contains functionality to generate code involving a shell, file or stream
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-04-16 01:07:31 UTC
File Type:
Text (JavaScript)
AV detection:
5 of 38 (13.16%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:donutloader family:remcos botnet:april 16th discovery execution loader persistence rat
Behaviour
Scheduled Task/Job: Scheduled Task
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Uses Task Scheduler COM API
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Checks computer location settings
Executes dropped EXE
Detects DonutLoader
Family: DonutLoader
Family: Remcos
Malware Config
C2 Extraction:
107.172.13.249:9010
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments