🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 736dc94a8570184dcc4e9e8ca45861c15fed381ee6eb696ecd9efbfb556da1a7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: 736dc94a8570184dcc4e9e8ca45861c15fed381ee6eb696ecd9efbfb556da1a7
SHA3-384 hash: a38b103c73714cc855df490ed93a9e6e5dde5dd4af1b5eefd2874680b145f3f2860015b89d2d0e0da3b0e56340ad605f
SHA1 hash: d0f19bb67388e3bb46ac9bd1fb40b2beb3e73994
MD5 hash: 0ebfe765ba43c9acd584e1ef8586975a
humanhash: eleven-social-north-july
File name:DHL_DOC75735835395935853958945634747535.bat
Download: download sample
Signature RemcosRAT
File size:5'939 bytes
First seen:2026-10-05 09:43:40 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 96:y9wae6vrSDUfXWC0Xu7FEwx08TY14OkiRIv4AUXKJiL:ySaZoUXSIFEwQqOtRIvRAK4L
TLSH T1BFC198606314710408963A64A47FCA0522FB4BBE21A9EE48B7F8B94EFCBD574437D5CC
Magika batch
Reporter lowmal3
Tags:bat RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
bat
Verdict:
No threats detected
Analysis date:
2026-10-05 10:47:19 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Launching cmd.exe command interpreter
Launching a process
Connection attempt to an infection source
Sending a TCP request to an infection source
Query of malicious DNS domain
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 cmd crypto encrypted lolbin masquerade powershell
Verdict:
Clean
File Type:
ps1
First seen:
2026-10-05T05:53:00Z UTC
Last seen:
2026-10-07T07:29:00Z UTC
Hits:
~1000
Result
Threat name:
Remcos, GuLoader
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Detected Remcos RAT
Found hidden mapped module (file has been removed from disk)
Found malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Hides threads from debuggers
Hijacks the control flow in another process
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Obfuscated command line found
Powershell connects to network
Sigma detected: Remcos
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected GuLoader
Yara detected Remcos RAT
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1982298 Sample: DHL_DOC75735835395935853958... Startdate: 05/10/2026 Architecture: WINDOWS Score: 100 92 westy04.karslioglu4-tr.com 2->92 94 privupload.linkpc.net 2->94 96 9 other IPs or domains 2->96 112 Suricata IDS alerts for network traffic 2->112 114 Found malware configuration 2->114 116 Malicious sample detected (through community Yara rule) 2->116 118 13 other signatures 2->118 12 cmd.exe 1 2->12         started        15 powershell.exe 19 2->15         started        17 powershell.exe 2->17         started        19 svchost.exe 1 1 2->19         started        signatures3 process4 dnsIp5 172 Suspicious powershell command line found 12->172 174 Wscript starts Powershell (via cmd or directly) 12->174 22 powershell.exe 1 18 12->22         started        26 conhost.exe 12->26         started        28 cmd.exe 1 12->28         started        30 powershell.exe 15 15->30         started        32 conhost.exe 15->32         started        34 powershell.exe 17->34         started        36 conhost.exe 17->36         started        98 127.0.0.1 unknown unknown 19->98 signatures6 process7 dnsIp8 100 privupload.linkpc.net 194.59.183.170, 443, 49701, 49728 OVHFR Germany 22->100 138 Hijacks the control flow in another process 22->138 140 Writes to foreign memory regions 22->140 142 Found suspicious powershell code related to unpacking or dynamic code loading 22->142 144 Switches to a custom stack to bypass stack traces 22->144 38 backgroundTaskHost.exe 9 14 22->38         started        43 backgroundTaskHost.exe 22->43         started        146 Installs a global keyboard hook 26->146 148 Hides threads from debuggers 30->148 45 backgroundTaskHost.exe 30->45         started        47 backgroundTaskHost.exe 30->47         started        49 backgroundTaskHost.exe 34->49         started        51 backgroundTaskHost.exe 34->51         started        signatures9 process10 dnsIp11 102 macos3.macosnimba3.name 34.41.139.193, 49712, 49713, 49715 GOOGLE-CLOUD-PLATFORM-GoogleLLCUS United States 38->102 104 macos.macosnimba.name 104.250.169.100, 49724, 49725, 49726 CDNEXTGB United Kingdom 38->104 106 elproexbacau.ro 89.42.218.71, 443, 49711, 49716 ROMARGRO Romania 38->106 84 C:\Users\user\AppData\Local\Temp\THE2C4.tmp, MS-DOS 38->84 dropped 86 C:\Users\user\AppData\Local\Temp\TH1D98.tmp, MS-DOS 38->86 dropped 88 C:\Users\user\AppData\Local\Temp\TH150A.tmp, MS-DOS 38->88 dropped 90 2 other malicious files 38->90 dropped 150 Detected Remcos RAT 38->150 152 Writes to foreign memory regions 38->152 154 Maps a DLL or memory area into another process 38->154 156 Installs a global keyboard hook 38->156 53 wscript.exe 38->53         started        56 cmd.exe 1 38->56         started        58 userinit.exe 38->58         started        64 5 other processes 38->64 158 Found hidden mapped module (file has been removed from disk) 43->158 160 Unusual module load detection (module proxying) 43->160 162 Switches to a custom stack to bypass stack traces 43->162 164 Hides threads from debuggers 45->164 60 backgroundTaskHost.exe 45->60         started        62 backgroundTaskHost.exe 49->62         started        file12 signatures13 process14 signatures15 120 Wscript starts Powershell (via cmd or directly) 53->120 122 Obfuscated command line found 53->122 124 Windows Scripting host queries suspicious COM object (likely to drop second stage) 53->124 136 2 other signatures 53->136 66 cmd.exe 53->66         started        69 conhost.exe 56->69         started        71 reg.exe 1 1 56->71         started        126 Tries to steal Mail credentials (via file registry) 58->126 128 Unusual module load detection (module proxying) 58->128 130 Tries to steal Instant Messenger accounts or passwords 64->130 132 Tries to steal Mail credentials (via file / registry access) 64->132 134 Tries to harvest and steal browser information (history, passwords, etc) 64->134 process16 signatures17 108 Wscript starts Powershell (via cmd or directly) 66->108 73 powershell.exe 66->73         started        76 conhost.exe 66->76         started        78 cmd.exe 66->78         started        110 Installs a global keyboard hook 69->110 process18 signatures19 166 Writes to foreign memory regions 73->166 168 Powershell connects to network 73->168 80 backgroundTaskHost.exe 73->80         started        82 backgroundTaskHost.exe 73->82         started        170 Installs a global keyboard hook 76->170 process20
Threat name:
Script-BAT.Trojan.Heuristic
Status:
Malicious
First seen:
2026-10-04 23:11:30 UTC
File Type:
Text (Batch)
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:guloader family:remcos botnet:bombadier collection defense_evasion discovery downloader execution persistence privilege_escalation rat suricata
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Suspicious use of NtCreateThreadExHideFromDebugger
Suspicious use of NtSetInformationThreadHideFromDebugger
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Accesses Microsoft Outlook profiles
Adds Run key to start application
Enumerates connected drives
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Detected Nirsoft tools
Family: Guloader,Cloudeye
Family: Remcos
Suricata alert: REMCOS RAT Malware Inbound C2 Communication
Suricata alert: REMCOS RAT Malware Outbound C2 Communication
Malware Config
C2 Extraction:
macos.macosnimba.name:57700
macos2.macosnimba2.name:57700
macos3.macosnimba3.name:57700
westy04.karslioglu4-tr.com:57700
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

Batch (bat) bat 736dc94a8570184dcc4e9e8ca45861c15fed381ee6eb696ecd9efbfb556da1a7

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments