MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8900715c5831700ecf8c7a089e0e30511f02f64ec34eba0ab02da4b4f00a37e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: a8900715c5831700ecf8c7a089e0e30511f02f64ec34eba0ab02da4b4f00a37e
SHA3-384 hash: 6ee3a8a184452b47658cb385f220c21150d17997d20bdb3af4a54c21f7431c877536adb800bb745c83454efb38c87666
SHA1 hash: 1977c3eab0289dc6f8420040dd7e73e796782647
MD5 hash: f8882301be15d016c9d9c42dfadb8240
humanhash: lithium-yankee-echo-oxygen
File name:Launcher.exe
Download: download sample
Signature RemusStealer
File size:80'886'807 bytes
First seen:2026-08-15 08:36:03 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash b34f154ec913d2d2c435cbd644e91687 (592 x GuLoader, 130 x RemcosRAT, 84 x EpsilonStealer)
ssdeep 1572864:tLdkpuBPaP33FIABZI48z2Fi/S8JKBUmy+N5Xe6EfB7b7:t2CUnaABZVPArg/bXeB7b7
TLSH T1C108334056608614D09F9FF9A13F2BE6EF1A1EE0B109E46B06564972F4FA4B7C6DC08F
TrID 50.3% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
10.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
10.5% (.EXE) Win64 Executable (generic) (6522/11/2)
8.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
7.2% (.EXE) Win32 Executable (generic) (4504/4/1)
Magika pebin
dhash icon b2a89c96a2cada72 (2'283 x Formbook, 981 x Loki, 803 x AgentTesla)
Reporter burger
Tags:exe RemusStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
194
Origin country :
SE SE
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
exe
Verdict:
No threats detected
Analysis date:
2026-08-15 08:40:05 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file in the %temp% subdirectories
Searching for the window
Сreating synchronization primitives
Creating a process from a recently created file
Creating a window
Running batch commands
Creating a process with a hidden window
Creating a file
Searching for synchronization primitives
Launching the process to interact with network services
Forced system process termination
Launching a process
Creating a file in the %AppData% subdirectories
Moving a file to the %AppData% subdirectory
Deleting a recently created file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
adaptive-context anti-debug anti-vm base64 crypto crypto expand expired-cert fingerprint hacktool installer installer lolbin microsoft_visual_cc nsis obfuscated reconnaissance
Verdict:
Malicious
File Type:
exe x32
Detections:
HEUR:Trojan.Script.Agent.gen
Result
Threat name:
REMUS Stealer
Detection:
malicious
Classification:
troj.spyw.evad.mine
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
Adds extensions / path to Windows Defender exclusion list
Adds extensions / path to Windows Defender exclusion list (Registry)
Antivirus detection for URL or domain
Bypasses PowerShell execution policy
Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners)
Drops large PE files
Encrypted powershell cmdline option found
Found malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suspicious powershell command line found
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Tries to steal from password manager
Unusual module load detection (module proxying)
Uses cmd line tools excessively to alter registry or file data
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript called in batch mode (surpress errors)
Yara detected REMUS Stealer
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1958515 Sample: Launcher.exe Startdate: 15/08/2026 Architecture: WINDOWS Score: 100 70 bravplo.click 2->70 72 www.google.com 2->72 74 4 other IPs or domains 2->74 94 Found malware configuration 2->94 96 Antivirus detection for URL or domain 2->96 98 Multi AV Scanner detection for submitted file 2->98 100 7 other signatures 2->100 10 Launcher.exe 189 2->10         started        14 explorer.exe 2->14         started        signatures3 process4 file5 60 C:\Users\user\AppData\Local\...\Installer.exe, PE32+ 10->60 dropped 62 C:\Users\user\AppData\Local\...\nsis7z.dll, PE32 10->62 dropped 64 C:\Users\user\AppData\Local\...\System.dll, PE32 10->64 dropped 66 10 other files (none is malicious) 10->66 dropped 130 Drops large PE files 10->130 16 Installer.exe 40 10->16         started        21 payload.exe 14->21         started        signatures6 process7 dnsIp8 68 192.162.199.149, 49754, 80 FEMOITGB United Kingdom 16->68 54 C:\Users\user\AppData\...\payload.exe.tmp, PE32+ 16->54 dropped 56 C:\Users\user\AppData\...\payload.exe (copy), PE32+ 16->56 dropped 58 C:\Users\user\AppData\...\dpinst_ca0480.vbs, ASCII 16->58 dropped 80 Adds extensions / path to Windows Defender exclusion list 16->80 82 Adds a directory exclusion to Windows Defender 16->82 84 Unusual module load detection (module proxying) 16->84 23 payload.exe 16->23         started        27 cmd.exe 1 16->27         started        29 cmd.exe 16->29         started        31 31 other processes 16->31 86 Tries to harvest and steal ftp login credentials 21->86 88 Tries to harvest and steal browser information (history, passwords, etc) 21->88 90 Tries to steal Crypto Currency Wallets 21->90 92 Tries to steal from password manager 21->92 file9 signatures10 process11 dnsIp12 76 bravplo.click 62.72.59.224, 49755, 49756, 49757 AS-HOSTINGERCY India 23->76 110 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 23->110 112 Found many strings related to Crypto-Wallets (likely being stolen) 23->112 114 Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners) 23->114 128 3 other signatures 23->128 116 Suspicious powershell command line found 27->116 118 Encrypted powershell cmdline option found 27->118 120 Bypasses PowerShell execution policy 27->120 33 conhost.exe 27->33         started        122 Adds a directory exclusion to Windows Defender 29->122 35 powershell.exe 29->35         started        38 conhost.exe 29->38         started        78 chrome.cloudflare-dns.com 172.64.41.3, 443, 49752, 49753 CLOUDFLARENET-CloudflareIncUS Canada 31->78 124 Uses cmd line tools excessively to alter registry or file data 31->124 126 Wscript called in batch mode (surpress errors) 31->126 40 reg.exe 1 31->40         started        42 wscript.exe 31->42         started        44 reg.exe 31->44         started        46 55 other processes 31->46 signatures13 process14 signatures15 102 Loading BitLocker PowerShell Module 35->102 104 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 40->104 106 Windows Scripting host queries suspicious COM object (likely to drop second stage) 42->106 108 Adds extensions / path to Windows Defender exclusion list (Registry) 44->108 48 net1.exe 1 46->48         started        50 net1.exe 1 46->50         started        52 payload.exe 46->52         started        process16
Gathering data
Result
Malware family:
n/a
Score:
  10/10
Tags:
defense_evasion discovery execution trojan
Behaviour
Modifies registry class
Runs net.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Hide Artifacts: Ignore Process Interrupts
Executes a VBScript file via the Windows Script Host.
Hide Artifacts: Hidden Window
Obfuscated Files or Information: Command Obfuscation
Checks computer location settings
Executes dropped EXE
Loads dropped DLL
Prevents Microsoft Defender from scanning certain paths by adding an exclusion.
System Binary Proxy Execution: Rundll32
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Windows security bypass
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

RemusStealer

Executable exe a8900715c5831700ecf8c7a089e0e30511f02f64ec34eba0ab02da4b4f00a37e

(this sample)

Comments