MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aa56b3f4ffd5008a12587e58568bd0334f0c5d131dfa7c2f853b2a9729dd2e53. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: aa56b3f4ffd5008a12587e58568bd0334f0c5d131dfa7c2f853b2a9729dd2e53
SHA3-384 hash: 926b2d0d4e179d1c6dc5d83a70787afbbde58b29e63babe56e2bcaa79b58e04509fccadf56204203459993a9df52d0ea
SHA1 hash: 23eb2235691eacfe5fd9a3f1b661a85f0cce90cd
MD5 hash: e10d77046b1e3239dba33e4b6cd05d5f
humanhash: bulldog-gee-river-mike
File name:IMG08042026.js
Download: download sample
Signature RemcosRAT
File size:1'006'319 bytes
First seen:2026-08-04 09:03:32 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 768:5MUr47dV7dB71naen57KCCP1YF0Y7F7jB0/FuYnu7pCpqm2YOVaanpvhW17JTRni:M5
TLSH T12E254CC7C916F7169AA061A3AD320E2ACBFF045A74E6A0593424D5FA33D2474CE1D9FC
Magika javascript
Reporter abuse_ch
Tags:js RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
164
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
js
First seen:
2026-08-04T03:53:00Z UTC
Last seen:
2026-08-06T07:38:00Z UTC
Hits:
~1000
Result
Threat name:
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Internet Explorer form passwords
Contains functionalty to change the wallpaper
Creates processes via WMI
Detected large data written to user environment variables, potentially indicating payload staging for fileless execution
Detected Remcos RAT
Excessive usage of taskkill to terminate processes
Found malware configuration
Injects a PE file into a foreign processes
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Performs DNS queries to domains with low reputation
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: Rare Remote Thread Creation By Uncommon Source Image
Sigma detected: Remcos
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Process Parents
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious command line found
Suspicious execution chain found
Suspicious powershell command line found
System process connects to network (likely due to code injection or exploit)
Tries to harvest and steal browser information (history, passwords, etc)
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Powershell decode and execute
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1951809 Sample: IMG08042026.js Startdate: 04/08/2026 Architecture: WINDOWS Score: 100 116 finterd.xyz 2->116 118 limidos.com 2->118 120 8 other IPs or domains 2->120 130 Suricata IDS alerts for network traffic 2->130 132 Found malware configuration 2->132 134 Malicious sample detected (through community Yara rule) 2->134 138 16 other signatures 2->138 12 powershell.exe 14 15 2->12         started        16 wscript.exe 2 2->16         started        18 cmd.exe 2->18         started        20 19 other processes 2->20 signatures3 136 Performs DNS queries to domains with low reputation 116->136 process4 dnsIp5 124 cxxz.co.za 86.107.77.91, 443, 49706 HOSTBETIN Germany 12->124 154 Suspicious powershell command line found 12->154 156 Writes to foreign memory regions 12->156 158 Suspicious command line found 12->158 160 Injects a PE file into a foreign processes 12->160 22 calc.exe 9 6 12->22         started        27 conhost.exe 12->27         started        162 Wscript starts Powershell (via cmd or directly) 16->162 164 Windows Scripting host queries suspicious COM object (likely to drop second stage) 16->164 166 Suspicious execution chain found 16->166 168 Detected large data written to user environment variables, potentially indicating payload staging for fileless execution 16->168 170 Creates processes via WMI 18->170 29 powershell.exe 18->29         started        31 Conhost.exe 18->31         started        33 powershell.exe 20->33         started        35 powershell.exe 20->35         started        37 powershell.exe 20->37         started        39 15 other processes 20->39 signatures6 process7 dnsIp8 122 limidos.com 217.60.195.118, 2404, 49717, 49718 NETPOOLIN Netherlands 22->122 108 C:\Users\user\AppData\Local\Temp\startv.js, ASCII 22->108 dropped 110 C:\Users\user\AppData\...\Login Data.tmp, SQLite 22->110 dropped 112 C:\Users\user\AppData\...\Login Data.tmp, SQLite 22->112 dropped 114 C:\Users\user\...\Login Data For Account.tmp, SQLite 22->114 dropped 142 System process connects to network (likely due to code injection or exploit) 22->142 144 Contains functionality to bypass UAC (CMSTPLUA) 22->144 146 Detected Remcos RAT 22->146 148 5 other signatures 22->148 41 wscript.exe 22->41         started        44 Acrobat.exe 57 22->44         started        46 powershell.exe 29->46         started        48 AppLaunch.exe 29->48         started        50 powershell.exe 33->50         started        52 AppLaunch.exe 33->52         started        54 2 other processes 35->54 56 2 other processes 37->56 58 11 other processes 39->58 file9 signatures10 process11 signatures12 150 Windows Scripting host queries suspicious COM object (likely to drop second stage) 41->150 152 Creates processes via WMI 41->152 60 AcroCEF.exe 78 44->60         started        62 cmd.exe 46->62         started        65 conhost.exe 46->65         started        67 cmd.exe 50->67         started        69 cmd.exe 50->69         started        71 conhost.exe 50->71         started        73 2 other processes 54->73 75 2 other processes 56->75 77 8 other processes 58->77 process13 signatures14 79 AcroCEF.exe 60->79         started        172 Excessive usage of taskkill to terminate processes 62->172 82 taskkill.exe 62->82         started        89 3 other processes 62->89 85 powershell.exe 67->85         started        87 Conhost.exe 67->87         started        91 4 other processes 69->91 93 8 other processes 73->93 95 4 other processes 75->95 97 16 other processes 77->97 process15 dnsIp16 126 23.45.136.167, 443, 49728 AKAMAI-AS-AkamaiTechnologiesIncUS United States 79->126 128 Suspicious powershell command line found 82->128 99 powershell.exe 85->99         started        101 AppLaunch.exe 85->101         started        signatures17 process18 process19 103 cmd.exe 99->103         started        106 conhost.exe 99->106         started        signatures20 140 Excessive usage of taskkill to terminate processes 103->140
Gathering data
Threat name:
Script-JS.Trojan.Heuristic
Status:
Malicious
First seen:
2026-08-04 09:36:22 UTC
File Type:
Text (JavaScript)
AV detection:
5 of 37 (13.51%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost adware collection defense_evasion discovery execution persistence rat spyware
Behaviour
Checks processor information in registry
Enumerates system info in registry
Kills process with taskkill
Modifies Internet Explorer settings
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
outlook_office_path
Browser Information Discovery
Command and Scripting Interpreter: JavaScript
Executes a command shell one-liner
System Location Discovery: System Language Discovery
System Time Discovery
Drops file in Windows directory
Suspicious use of SetThreadContext
Accesses Microsoft Outlook profiles
Adds Run key to start application
Contacts third-party web service commonly abused for C2
Badlisted process makes network request
Command and Scripting Interpreter: PowerShell
Family: Remcos
Process spawned unexpected child process
Malware Config
C2 Extraction:
limidos.com:2404
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments