🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7a0219d5c29818ff0164d22b66aa2125846b8d2d8caf918e7e6f38c0dc8dff76. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 11


Intelligence 11 IOCs 1 YARA File information Comments

SHA256 hash: 7a0219d5c29818ff0164d22b66aa2125846b8d2d8caf918e7e6f38c0dc8dff76
SHA3-384 hash: d192e8748a7fd921dc7044a74260b87e6b3f66cf7cad721c3c65b7331586e64d5224b2d43b9a64839053cebf6c5ba148
SHA1 hash: c0d175743e77e63a15d040065bdcaf48644b2c39
MD5 hash: c917bff2167fcd8d97ad6eec8d96d0fc
humanhash: arkansas-glucose-kitten-delaware
File name:STIVP-FIV-FMA-6349 - 01revCopies09092026.pdf..js
Download: download sample
Signature RemcosRAT
File size:4'822'322 bytes
First seen:2026-09-14 05:40:09 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 98304:u9VchGeWI5dKixKSI4sJwWDubgj2jZ71jFVoW6xdH/8NJy3JCsIhx8xCj0XjLg58:e8KwKSIPJw2Egj2jvjFf6PH/t0sIPb0h
TLSH T1F526F7552B48D1327B21EBAE5335CD30E81A512324C5DBA1357CEB083B6CE4BA75DEE2
Magika javascript
Reporter abuse_ch
Tags:js RAT RemcosRAT


Avatar
abuse_ch
RemcosRAT C2:
43.228.157.171:2404

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
43.228.157.171:2404 https://threatfox.abuse.ch/ioc/1916607/

Intelligence


File Origin
# of uploads :
1
# of downloads :
187
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-14T01:50:00Z UTC
Last seen:
2026-09-15T23:57:00Z UTC
Hits:
~100
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
JavaScript source code contains functionality to generate code involving a shell, file or stream
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Trojan.Egairtigado
Status:
Malicious
First seen:
2026-09-14 05:40:26 UTC
File Type:
Text (JavaScript)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:donutloader family:remcos execution loader rat suricata
Behaviour
Modifies registry class
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Detects DonutLoader
Family: DonutLoader
Family: Remcos
Suricata alert: REMCOS RAT Malware Inbound C2 Communication
Suricata alert: REMCOS RAT Malware Outbound C2 Communication
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments