🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a51cd82b5a79b11cdbdb00cff26c7fd39ad6a4a5b410d2d20d3219527b93e595. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: a51cd82b5a79b11cdbdb00cff26c7fd39ad6a4a5b410d2d20d3219527b93e595
SHA3-384 hash: 1b2e9fc349354b6f95bb9c308e79903e963c41e741ce58f8376cc4c7150b644ec92b90dba262a79963b967c5e71b5b6b
SHA1 hash: 54bd75c4d1cbb2ba0063f8d0f87fc9b4c82b4c4a
MD5 hash: 0c4e996f6dda7c5b0cbf642a30ac0d55
humanhash: shade-yellow-utah-vermont
File name:e_a1f8d3b7c2e9_decrypted.pyd
Download: download sample
Signature RemcosRAT
File size:1'643'008 bytes
First seen:2026-09-16 20:48:17 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 47e2409fc443c0a0b96a2bd59ce69e10 (1 x RemcosRAT)
ssdeep 24576:LXqH3zPi3TkmDQLyRenkueYzy47VViKriRjZgie7FPi/4Jd15kNjFeSexq4:C3zqonVeY2AiKSdg1oY
TLSH T11575F72323B40006FBB685F64D6AE773DEB2B9CA1B5232D700A0DA9837D7DD656EC144
TrID 29.5% (.EXE) Win64 Executable (generic) (6522/11/2)
22.8% (.EXE) Win16 NE executable (generic) (5038/12/1)
20.3% (.EXE) Win32 Executable (generic) (4504/4/1)
9.1% (.EXE) OS/2 Executable (generic) (2029/13)
9.0% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
Reporter GhostTypes
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
104
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-09-16 20:54:51 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade microsoft_visual_cc nuitka packed packed
Verdict:
Unknown
File Type:
dll x64
First seen:
2026-06-26T18:38:00Z UTC
Last seen:
2026-09-16T11:00:00Z UTC
Hits:
~10
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Win 64 Exe x64
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Unpacked files
SH256 hash:
a51cd82b5a79b11cdbdb00cff26c7fd39ad6a4a5b410d2d20d3219527b93e595
MD5 hash:
0c4e996f6dda7c5b0cbf642a30ac0d55
SHA1 hash:
54bd75c4d1cbb2ba0063f8d0f87fc9b4c82b4c4a
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments