MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f6f052595b109f4e8fdf42644b98f6380635f3f45f280cf85aacf6e30e30d2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 14


Intelligence 14 IOCs YARA 19 File information Comments

SHA256 hash: 6f6f052595b109f4e8fdf42644b98f6380635f3f45f280cf85aacf6e30e30d2e
SHA3-384 hash: 9e970a8f21f6bc0701d7bfa3d4fb3fd3d0a9c75b943c6d73d71359e53bde0e88070554b87471b7df3227012b32264c8b
SHA1 hash: 15b307e718515da11a94bbe0d37ea0e36e851e3c
MD5 hash: d22008ef5f97d9f3a4f93e7642630596
humanhash: wolfram-summer-lithium-low
File name:cry.exe
Download: download sample
Signature RemusStealer
File size:1'892'560 bytes
First seen:2026-05-26 00:19:54 UTC
Last seen:2026-05-26 00:21:40 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash ebc247a77b4d4a804b261f97a1fd075c (89 x Vidar, 26 x Smoke Loader, 16 x RemusStealer)
ssdeep 24576:O2MTpumWDSc72i8bQsBpHQfR2XbCM7YPlfmrMtPlnqj5y:O2M0JDSc72vbQpfR2XbCSQAr6nAy
TLSH T181955B0ABCE048F6D06AA3328DB625927B72BC190F3223D32E90B5792F776D49D75750
TrID 33.1% (.EXE) Win64 Executable (generic) (6522/11/2)
25.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
10.4% (.ICL) Windows Icons Library (generic) (2059/9)
10.3% (.EXE) OS/2 Executable (generic) (2029/13)
10.1% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 33d0dcf4f0f0500f (1 x RemusStealer)
Reporter aachum
Tags:5-252-155-72 exe orderre-shop RemusStealer signed

Code Signing Certificate

Organisation:sedo.com
Issuer:Sectigo Public Server Authentication CA DV R36
Algorithm:sha256WithRSAEncryption
Valid from:2026-04-07T00:00:00Z
Valid to:2026-10-22T23:59:59Z
Serial number: 0f8257ea30dd2749fbbe780c1cd3f3ef
Intelligence: 2 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 73d8d22c350ba661e7dd1edcb5cd9a57733bc9eedc12c68e25e1141c69eea9e2
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform


Avatar
iamaachum
http://5.252.155.72/load/os1/cry.exe

RemusStealer C2:
orderre.shop (153.75.226.95:4190)

Intelligence


File Origin
# of uploads :
2
# of downloads :
123
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
cry.exe
Verdict:
Malicious activity
Analysis date:
2026-05-26 00:16:23 UTC
Tags:
golang

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
92.5%
Tags:
injection obfusc crypt
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP POST request
Connection attempt to an infection source
Query of malicious DNS domain
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-vm crypto golang signed stealer
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-05-25T21:19:00Z UTC
Last seen:
2026-05-26T22:15:00Z UTC
Hits:
~100
Detections:
Backdoor.Win64.Gsb.sb Backdoor.Win64.Gsb.gen VHO:Backdoor.Win64.GoBin.gen
Result
Threat name:
HijackLoader, Vidar
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contain functionality to detect virtual machines
Creates a thread in another existing process (thread injection)
Found direct / indirect Syscall (likely to bypass EDR)
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Passes commands via pipe to a shell (likely to bypass AV or HIPS)
Potentially malicious time measurement code found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Suricata IDS alerts for network traffic
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Uses known network protocols on non-standard ports
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Yara detected HijackLoader
Yara detected Vidar stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1918344 Sample: cry.exe Startdate: 26/05/2026 Architecture: WINDOWS Score: 100 92 updatecheck310.activated.win 2->92 94 orderre.shop 2->94 96 18 other IPs or domains 2->96 134 Suricata IDS alerts for network traffic 2->134 136 Found malware configuration 2->136 138 Malicious sample detected (through community Yara rule) 2->138 140 10 other signatures 2->140 15 cry.exe 1 2->15         started        signatures3 process4 dnsIp5 100 femade.co.uk 68.65.122.46, 443, 49701 NAMECHEAP-NET-NamecheapIncUS United States 15->100 102 orderre.shop 153.75.226.95, 4190, 49684 IS-AS-1-InterserverIncUS United States 15->102 104 fiinterchillers.com 173.231.216.118, 443, 49700 IMH-IAD-InMotionHostingIncUS United States 15->104 60 C:\...\8JkBoLPNceV9L2o5643yHPiDgJ7quq.exe, PE32 15->60 dropped 122 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 15->122 124 Query firmware table information (likely to detect VMs) 15->124 126 Tries to steal Mail credentials (via file / registry access) 15->126 128 7 other signatures 15->128 20 8JkBoLPNceV9L2o5643yHPiDgJ7quq.exe 13 15->20         started        file6 signatures7 process8 file9 62 C:\Users\user\AppData\Local\Temp\vcl120.bpl, PE32 20->62 dropped 64 C:\Users\user\AppData\Local\...\ucrtbase.dll, PE32 20->64 dropped 66 C:\Users\user\AppData\Local\Temp\rtl120.bpl, PE32 20->66 dropped 68 6 other malicious files 20->68 dropped 23 DeltaGen32.exe 12 20->23         started        process10 file11 70 C:\ProgramData\...\vcl120.bpl, PE32 23->70 dropped 72 C:\ProgramData\...\ucrtbase.dll, PE32 23->72 dropped 74 C:\ProgramData\...\rtl120.bpl, PE32 23->74 dropped 76 6 other malicious files 23->76 dropped 142 Switches to a custom stack to bypass stack traces 23->142 144 Found direct / indirect Syscall (likely to bypass EDR) 23->144 27 DeltaGen32.exe 28 23->27         started        signatures12 process13 file14 78 C:\Users\user\AppData\Roaming\...\zlib1.dll, PE32 27->78 dropped 80 C:\Users\user\AppData\...\vmwarestring.dll, PE32 27->80 dropped 82 C:\Users\user\AppData\...\vmwarebase.dll, PE32 27->82 dropped 84 18 other malicious files 27->84 dropped 146 Modifies the context of a thread in another process (thread injection) 27->146 148 Found hidden mapped module (file has been removed from disk) 27->148 150 Maps a DLL or memory area into another process 27->150 152 2 other signatures 27->152 31 Transponder-Sonic.exe 9 27->31         started        35 AdaptiveSchedule.exe 27->35         started        signatures15 process16 dnsIp17 86 C:\Users\user\AppData\Roaming\...\Crisp.exe, PE32 31->86 dropped 88 C:\Users\user\AppData\Local\...\7EF3ABA.tmp, PE32 31->88 dropped 90 C:\Users\user\AppData\Local\SynthSer.exe, PE32 31->90 dropped 106 Contain functionality to detect virtual machines 31->106 108 Found hidden mapped module (file has been removed from disk) 31->108 110 Maps a DLL or memory area into another process 31->110 112 Switches to a custom stack to bypass stack traces 31->112 38 cmd.exe 1 31->38         started        98 65.109.251.186, 443, 49702, 49703 HETZNER-ASDE Finland 35->98 114 Tries to harvest and steal browser information (history, passwords, etc) 35->114 116 Tries to detect virtualization through RDTSC time measurements 35->116 118 Hides threads from debuggers 35->118 120 3 other signatures 35->120 file18 signatures19 process20 process21 40 cmd.exe 1 38->40         started        42 conhost.exe 38->42         started        process22 44 cmd.exe 1 40->44         started        47 conhost.exe 40->47         started        signatures23 154 Uses ping.exe to sleep 44->154 156 Uses cmd line tools excessively to alter registry or file data 44->156 158 Uses ping.exe to check the status of other devices and networks 44->158 160 Passes commands via pipe to a shell (likely to bypass AV or HIPS) 44->160 49 cmd.exe 44->49         started        52 cmd.exe 1 44->52         started        54 cmd.exe 1 44->54         started        56 17 other processes 44->56 process24 signatures25 130 Uses cmd line tools excessively to alter registry or file data 49->130 132 Passes commands via pipe to a shell (likely to bypass AV or HIPS) 49->132 58 cmd.exe 1 52->58         started        process26
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Kepavll
Status:
Malicious
First seen:
2026-05-26 00:16:52 UTC
File Type:
PE+ (Exe)
Extracted files:
4
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
snappyclient
Score:
  10/10
Tags:
family:hijackloader family:remus_stealer family:snappyclient botnet:7761302005f34d66ff5f26459abbcce2 backdoor credential_access discovery loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Modifies registry key
Runs ping.exe
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious behavior: MapViewOfSection
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Launches sc.exe
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Drops desktop.ini file(s)
Executes dropped EXE
Loads dropped DLL
Reads WinSCP keys stored on the system
Reads data files stored by FTP clients
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Unsecured Credentials: Credentials In Files
Downloads MZ/PE file
Detects HijackLoader (aka IDAT Loader)
Detects Remus stealer
Family: HijackLoader, IDAT loader, Ghostulse,
Family: Remus
Family: SnappyClient
Suspicious use of NtCreateProcessExOtherParentProcess
Malware Config
C2 Extraction:
http://orderre.shop:4190
http://firewai.biz:48261
http://woodfez.biz:7582
Unpacked files
SH256 hash:
6f6f052595b109f4e8fdf42644b98f6380635f3f45f280cf85aacf6e30e30d2e
MD5 hash:
d22008ef5f97d9f3a4f93e7642630596
SHA1 hash:
15b307e718515da11a94bbe0d37ea0e36e851e3c
Malware family:
RemusStealer
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:command_and_control
Author:CD_R0M_
Description:This rule searches for common strings found by malware using C2. Based on a sample used by a Ransomware group
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:GoBinTest
Rule name:golang
Rule name:Golangmalware
Author:Dhanunjaya
Description:Malware in Golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:Golang_Find_CSC846
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:Golang_Find_CSC846_Simple
Author:Ashar Siddiqui
Description:Find Go Signatuers
Rule name:HiveRansomware
Author:Dhanunjaya
Description:Yara Rule To Detect Hive V4 Ransomware
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:SEH__vectored
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Suspicious_Golang_Binary
Author:Tim Machac
Description:Triage: Golang-compiled binary with suspicious OS/persistence/network strings (not family-specific)
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemusStealer

Executable exe 6f6f052595b109f4e8fdf42644b98f6380635f3f45f280cf85aacf6e30e30d2e

(this sample)

Comments