🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98cecce7af563ef3ddf09739cddbb50dac918cef40b1d24e8e5c22079d2c0857. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 98cecce7af563ef3ddf09739cddbb50dac918cef40b1d24e8e5c22079d2c0857
SHA3-384 hash: 46a2355867b7adfcd6c9b8dfb74b0de0894d9e24a8892401e7fbae95c71c87df86dbd157a34028c0ea9a93661ddc9d01
SHA1 hash: 3fe3823d9b3b7418210b3ba0ce78881fe52e23c3
MD5 hash: d4de8464c02b1ef2d72c3f5a71c06291
humanhash: floor-crazy-diet-bluebird
File name:Payment Reference0013011100.js
Download: download sample
Signature RemcosRAT
File size:54'229 bytes
First seen:2026-09-28 11:29:08 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:37km3PAiVCtqTNxhrjui3A/mxTniA5X+EXKzrfDC+GOfj2GMcK+eIh2rGj1kkg1y:hqb4TlHArpG4T3wVLmDqyJNgTY5r
TLSH T198336132B2B3F70D9600A2448D16B8DEBBA44422571BDF83625971EEE77CD10EF66630
Magika javascript
Reporter threatcat_ch
Tags:js RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
189
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm encrypted fingerprint masquerade repaired
Verdict:
Suspicious
Labled as:
SVM:TrojanDownloader/JS.MalBehav.gen
Verdict:
Malicious
File Type:
js
First seen:
2026-09-28T08:19:00Z UTC
Last seen:
2026-09-29T10:08:00Z UTC
Hits:
~10000
Result
Threat name:
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to inject threads in other processes
Contains functionality to steal Internet Explorer form passwords
Creates processes via WMI
Detected large data written to user environment variables, potentially indicating payload staging for fileless execution
Found malware configuration
Found stalling execution ending in API Sleep call
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
JScript performs obfuscated calls to suspicious functions
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Powershell connects to network
Sample has a suspicious name (potential lure to open the executable)
Sigma detected: Dot net compiler compiles file from suspicious location
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes / dynamic malware analysis system (Installed program check)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file registry)
Unusual module load detection (module proxying)
Uses dynamic DNS services
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1978918 Sample: Payment Reference0013011100.js Startdate: 28/09/2026 Architecture: WINDOWS Score: 100 60 ocean012.duckdns.org 2->60 62 nd.tdpqnf.com 2->62 64 5 other IPs or domains 2->64 78 Suricata IDS alerts for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 86 12 other signatures 2->86 11 wscript.exe 2 2->11         started        14 svchost.exe 1 1 2->14         started        signatures3 84 Uses dynamic DNS services 60->84 process4 dnsIp5 96 JScript performs obfuscated calls to suspicious functions 11->96 98 Wscript starts Powershell (via cmd or directly) 11->98 100 Windows Scripting host queries suspicious COM object (likely to drop second stage) 11->100 102 3 other signatures 11->102 17 cmd.exe 1 11->17         started        74 127.0.0.1 unknown unknown 14->74 signatures6 process7 signatures8 76 Wscript starts Powershell (via cmd or directly) 17->76 20 powershell.exe 14 25 17->20         started        25 conhost.exe 17->25         started        process9 dnsIp10 66 idid.pl 77.55.252.101, 49699, 80 NETARTGROUPPL Poland 20->66 68 217.60.76.249 MICROLINK-CORE-MicrolinkNetworkUS Netherlands 20->68 70 2 other IPs or domains 20->70 50 C:\Users\user\AppData\...\t4bl0dzt.cmdline, Unicode 20->50 dropped 88 Suspicious powershell command line found 20->88 90 Writes to foreign memory regions 20->90 92 Modifies the context of a thread in another process (thread injection) 20->92 94 3 other signatures 20->94 27 RegAsm.exe 4 3 20->27         started        32 csc.exe 3 20->32         started        34 powershell.exe 10 20->34         started        file11 signatures12 process13 dnsIp14 72 ocean012.duckdns.org 84.38.133.167 DATACLUB-NLLV Netherlands 27->72 52 C:\Users\user\AppData\...\Login Data.tmp, SQLite 27->52 dropped 54 C:\Users\user\AppData\...\Login Data.tmp, SQLite 27->54 dropped 56 C:\Users\user\...\Login Data For Account.tmp, SQLite 27->56 dropped 104 Contains functionality to bypass UAC (CMSTPLUA) 27->104 106 Tries to steal Mail credentials (via file registry) 27->106 108 Found stalling execution ending in API Sleep call 27->108 110 5 other signatures 27->110 58 C:\Users\user\AppData\Local\...\t4bl0dzt.dll, PE32 32->58 dropped 36 cvtres.exe 1 32->36         started        38 cmd.exe 1 34->38         started        40 conhost.exe 34->40         started        file15 signatures16 process17 process18 42 taskkill.exe 1 38->42         started        44 taskkill.exe 1 38->44         started        46 taskkill.exe 1 38->46         started        48 conhost.exe 38->48         started       
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution
Behaviour
Kills process with taskkill
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Executes a command shell one-liner
Reads the TCP/IP host and domain name from the registry
Enumerates connected drives
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

Java Script (JS) js 98cecce7af563ef3ddf09739cddbb50dac918cef40b1d24e8e5c22079d2c0857

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments