MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b5ded751fcf17c56d5f8f9701397cc1e1f675437cd22dcd83f21c8f7a2ff107. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 1 File information Comments

SHA256 hash: 6b5ded751fcf17c56d5f8f9701397cc1e1f675437cd22dcd83f21c8f7a2ff107
SHA3-384 hash: fd00d40ff5f29e9a17d8a66efc7ec46e2e1ad464ea9885aa004a7db1be3f8db7188cc433a6745c337f04d4cfab51098a
SHA1 hash: 7291007991627dceb256f90ad37b21475bdff47b
MD5 hash: 5ca7aca0d13e284c50e3c046e3447bee
humanhash: paris-pip-kansas-failed
File name:SOA.js
Download: download sample
Signature RemcosRAT
File size:5'098'929 bytes
First seen:2026-08-26 07:51:36 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 49152:IUlkTiSNBRMgg4LzvrEpcWFSpFSuVOcLMuvmo35z3OFiD3OY0O9dm:h
TLSH T18036E6B72BFD65CA9E147AA5A44A1D888B8FD7B61F8352C0E0FF15E04E1F48B518052F
Magika javascript
Reporter abuse_ch
Tags:js RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-08-25T23:54:00Z UTC
Last seen:
2026-08-27T23:51:00Z UTC
Hits:
~100
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Creates autostart registry keys with suspicious names
Creates autostart registry keys with suspicious values (likely registry only malware)
Creates multiple autostart registry keys
Detected Remcos RAT
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Injects a PE file into a foreign processes
JavaScript file contains suspicious strings
JavaScript source code contains functionality to generate code involving a shell, file or stream
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Powershell decode and execute
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963905 Sample: SOA.js Startdate: 26/08/2026 Architecture: WINDOWS Score: 100 74 207.180.29.85 HVC-AS-HIVELOCITYIncUS United States 2->74 76 Found malware configuration 2->76 78 Malicious sample detected (through community Yara rule) 2->78 80 Multi AV Scanner detection for submitted file 2->80 82 9 other signatures 2->82 10 wscript.exe 2 4 2->10         started        13 powershell.exe 17 2->13         started        15 powershell.exe 17 2->15         started        17 3 other processes 2->17 signatures3 process4 signatures5 104 Suspicious powershell command line found 10->104 106 Wscript starts Powershell (via cmd or directly) 10->106 108 Creates autostart registry keys with suspicious values (likely registry only malware) 10->108 114 4 other signatures 10->114 19 powershell.exe 16 10->19         started        110 Writes to foreign memory regions 13->110 112 Injects a PE file into a foreign processes 13->112 22 aspnet_compiler.exe 13->22         started        24 aspnet_compiler.exe 13->24         started        26 conhost.exe 13->26         started        36 5 other processes 13->36 28 conhost.exe 15->28         started        30 conhost.exe 17->30         started        32 conhost.exe 17->32         started        34 conhost.exe 17->34         started        process6 signatures7 84 Writes to foreign memory regions 19->84 86 Found suspicious powershell code related to unpacking or dynamic code loading 19->86 88 Injects a PE file into a foreign processes 19->88 38 aspnet_compiler.exe 2 3 19->38         started        42 aspnet_compiler.exe 19->42         started        44 aspnet_compiler.exe 1 2 19->44         started        50 9 other processes 19->50 90 Detected Remcos RAT 22->90 46 remcos.exe 22->46         started        48 remcos.exe 24->48         started        process8 file9 72 C:\ProgramData\Remcos\remcos.exe, PE32 38->72 dropped 92 Detected Remcos RAT 38->92 94 Creates autostart registry keys with suspicious names 38->94 96 Creates multiple autostart registry keys 38->96 52 remcos.exe 2 38->52         started        98 Contains functionality to bypass UAC (CMSTPLUA) 42->98 100 Contains functionality to register a low level keyboard hook 42->100 102 Unusual module load detection (module proxying) 42->102 54 remcos.exe 44->54         started        56 conhost.exe 46->56         started        58 conhost.exe 48->58         started        60 remcos.exe 50->60         started        62 remcos.exe 50->62         started        signatures10 process11 process12 64 conhost.exe 52->64         started        66 conhost.exe 54->66         started        68 conhost.exe 60->68         started        70 conhost.exe 62->70         started       
Gathering data
Threat name:
Script-JS.Trojan.Acsogenixx
Status:
Malicious
First seen:
2026-08-26 07:52:40 UTC
File Type:
Text (JavaScript)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost discovery execution persistence privilege_escalation rat
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Creates a file in the Startup directory
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: Remcos
Malware Config
C2 Extraction:
207.180.29.85:2404
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Base64_Encoded_Powershell_Directives

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments