MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 15


Intelligence 15 IOCs YARA 14 File information Comments

SHA256 hash: 86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a
SHA3-384 hash: 6cfff44a139d2201adea405a179c14cce2c86cf76bb983948121c33289497818ac944691062b56d9aa76e50071055849
SHA1 hash: 863adf6289db25fdc4ac0ef2e1a2ae63d43366b9
MD5 hash: 0054d2622e335797a8697982af417982
humanhash: juliet-sink-edward-asparagus
File name:Setup.exe
Download: download sample
Signature RemusStealer
File size:15'646'329 bytes
First seen:2026-08-25 20:17:07 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (80 x RemusStealer, 5 x ValleyRAT, 5 x SalatStealer)
ssdeep 393216:Psr//yRj3zzD2I8Pm0eBkXnZAKcQYFh2kvvJYxXxSyXK+o:P9Rj3zGI8kBONcXh2a6PXJo
TLSH T1C5F63305A76031ABFCB29134DFE786D0DB72780B072495EB27E4A95B1FA71D1CB2A710
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (915 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter aachum
Tags:ClickFraud exe gcleaner RemusStealer sfx unluckytool-com


Avatar
iamaachum
https://winds11.site/aa/Setup.rar

RemusStealer C2:
http://goldeth.click :6572/users
http://kupzovo.shop:7567/users
http://vexdico.shop:8539/messages
GCleaner C2:
91.92.242.236

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
ES ES
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Creating a process from a recently created file
Creating a process with a hidden window
Launching a service
Using the Windows Management Instrumentation requests
Creating a file in the %temp% subdirectories
Launching a process
Deleting a recently created file
DNS request
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Changing a file
Reading critical registry keys
Replacing files
Moving a recently created file
Unauthorized injection to a recently created process
Connection attempt to an infection source
Query of malicious DNS domain
Unauthorized injection to a system process
Sending an HTTP GET request to an infection source
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug cmd fingerprint golang installer installer installer-heuristic large-file lolbin microsoft_visual_cc msbuild overlay packed powershell reconnaissance sfx
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-08-25T18:24:00Z UTC
Last seen:
2026-08-25T18:45:00Z UTC
Hits:
~10
Result
Threat name:
GCleaner, GO Stealer, REMUS Stealer
Detection:
malicious
Classification:
phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
AI detected malicious page (phishing or scam)
Allocates memory in foreign processes
Antivirus detection for dropped file
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Creates a thread in another existing process (thread injection)
Drops large PE files
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious webpage
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Tries to steal Mail credentials (via file / registry access)
Unusual module load detection (module proxying)
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected GCleaner
Yara detected GO Stealer
Yara detected PhishFingerprint
Yara detected REMUS Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963654 Sample: Setup.exe Startdate: 25/08/2026 Architecture: WINDOWS Score: 100 123 45.91.200.135 PODAONLV Netherlands 2->123 125 185.156.73.98 FDN3UA Netherlands 2->125 127 16 other IPs or domains 2->127 161 Suricata IDS alerts for network traffic 2->161 163 Found malware configuration 2->163 165 Antivirus detection for URL or domain 2->165 167 16 other signatures 2->167 15 Setup.exe 3 9 2->15         started        19 svchost.exe 2->19         started        21 unsecapp.exe 2->21         started        23 unsecapp.exe 2->23         started        signatures3 process4 file5 117 C:\Users\user\Desktop\appFile.exe, PE32+ 15->117 dropped 119 C:\Users\user\Desktop\ae_mixtwo.exe, PE32 15->119 dropped 121 C:\Users\user\Desktop\OpenLink.ps1, ASCII 15->121 dropped 151 Drops large PE files 15->151 25 ae_mixtwo.exe 10 15->25         started        29 appFile.exe 15->29         started        32 wscript.exe 1 15->32         started        signatures6 process7 dnsIp8 99 C:\Users\user\AppData\Local\Temp\...\re21.exe, PE32+ 25->99 dropped 181 Multi AV Scanner detection for dropped file 25->181 183 Writes to foreign memory regions 25->183 185 Allocates memory in foreign processes 25->185 187 Injects a PE file into a foreign processes 25->187 34 MSBuild.exe 25 25->34         started        39 re21.exe 3 25->39         started        147 practisingcertificateprotection.com 176.53.159.66 ORACLE-BMC-31898-OracleCorporationUS Turkey 29->147 189 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 29->189 191 Tries to steal Mail credentials (via file / registry access) 29->191 193 Found many strings related to Crypto-Wallets (likely being stolen) 29->193 201 5 other signatures 29->201 195 Suspicious powershell command line found 32->195 197 Wscript starts Powershell (via cmd or directly) 32->197 199 Bypasses PowerShell execution policy 32->199 203 3 other signatures 32->203 41 powershell.exe 32->41         started        file9 signatures10 process11 dnsIp12 129 91.92.242.236, 49761, 80 OMEGATECH-ASSC Netherlands 34->129 131 drive.usercontent.google.com 142.251.211.129, 443, 49760 GOOGLE-GoogleLLCUS United States 34->131 91 C:\Users\user\AppData\...\8DYUlu7LJuM.exe, PE32 34->91 dropped 93 C:\Users\user\AppData\...\qyNVRRNSK6gt.exe, PE32+ 34->93 dropped 95 C:\Users\user\AppData\...\oLWuv9Vcwtbr.exe, PE32+ 34->95 dropped 97 3 other malicious files 34->97 dropped 169 Unusual module load detection (module proxying) 34->169 43 8DYUlu7LJuM.exe 34->43         started        47 69ehgDLPH.exe 34->47         started        49 qyNVRRNSK6gt.exe 34->49         started        58 2 other processes 34->58 171 Multi AV Scanner detection for dropped file 39->171 173 Writes to foreign memory regions 39->173 175 Modifies the context of a thread in another process (thread injection) 39->175 177 Injects a PE file into a foreign processes 39->177 51 MSBuild.exe 39->51         started        179 Found many strings related to Crypto-Wallets (likely being stolen) 41->179 54 chrome.exe 41->54         started        56 conhost.exe 41->56         started        file13 signatures14 process15 dnsIp16 103 C:\Users\user\AppData\...\8DYUlu7LJuM.tmp, PE32 43->103 dropped 205 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 43->205 60 8DYUlu7LJuM.tmp 43->60         started        64 conhost.exe 47->64         started        66 conhost.exe 49->66         started        133 vexdico.shop 165.227.199.109, 49804, 8539 DIGITALOCEAN-ASN-DigitalOceanLLCUS United States 51->133 207 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 51->207 209 Unusual module load detection (module proxying) 51->209 135 192.168.2.5, 443, 49732, 49733 unknown unknown 54->135 137 192.168.2.6 unknown unknown 54->137 139 192.168.2.9 unknown unknown 54->139 68 chrome.exe 54->68         started        71 conhost.exe 58->71         started        file17 signatures18 process19 dnsIp20 105 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 60->105 dropped 211 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 60->211 73 8DYUlu7LJuM.exe 60->73         started        141 www.google.com 142.251.156.119, 443, 49766, 49772 GOOGLE-GoogleLLCUS United States 68->141 143 mobile-gtalk.l.google.com 172.253.139.188, 49787, 5228 GOOGLE-GoogleLLCUS United States 68->143 145 7 other IPs or domains 68->145 107 Chrome Cache Entry: 317, PDP-11 68->107 dropped file21 signatures22 process23 file24 101 C:\Users\user\AppData\...\8DYUlu7LJuM.tmp, PE32 73->101 dropped 76 8DYUlu7LJuM.tmp 73->76         started        process25 file26 109 C:\Users\user\AppData\Local\...\_isdecmp.dll, PE32 76->109 dropped 111 C:\ProgramData\...\vcruntime140_1.dll (copy), PE32+ 76->111 dropped 113 C:\ProgramData\...\vcruntime140.dll (copy), PE32+ 76->113 dropped 115 10 other malicious files 76->115 dropped 79 FnHotkeyUtility.exe 76->79         started        process27 dnsIp28 149 193.221.201.195 NEONCORENETWORKSUS Netherlands 79->149 153 Found many strings related to Crypto-Wallets (likely being stolen) 79->153 155 Tries to harvest and steal browser information (history, passwords, etc) 79->155 157 Writes to foreign memory regions 79->157 159 4 other signatures 79->159 83 chrome.exe 79->83         started        85 msedge.exe 79->85         started        87 WerFault.exe 79->87         started        signatures29 process30 process31 89 WerFault.exe 83->89         started       
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.20 SOS: 0.21 SOS: 0.92 Win 64 Exe x64
Threat name:
ByteCode-MSIL.Trojan.Injectornett
Status:
Malicious
First seen:
2026-08-25 20:18:21 UTC
File Type:
PE+ (Exe)
Extracted files:
63
AV detection:
18 of 36 (50.00%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:gcleaner family:remus_stealer discovery execution loader spyware stealer
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Checks computer location settings
Executes dropped EXE
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Family: GCleaner
Family: Remus
Malware Config
C2 Extraction:
http://goldeth .click :6572/users
http://kupzovo.shop:7567/users
http://vexdico.shop:8539/messages
185.156.73.98
45.91.200.135
Dropper Extraction:
https://wappingerbicornshaps.com/s4r7aa2f7f74b7ac2ab0af7589004c3a8ef07971edb98
Unpacked files
SH256 hash:
86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a
MD5 hash:
0054d2622e335797a8697982af417982
SHA1 hash:
863adf6289db25fdc4ac0ef2e1a2ae63d43366b9
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemusStealer

Executable exe 86f27425624e99fca1a6735b4ed5e192f575794e57f16c47a1e068bb1e608d6a

(this sample)

  
Delivery method
Distributed via web download

Comments