🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae1a58b73c14de3d0d4af02ac0c136a4e804ed1a911de386fa40208672611309. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 18


Intelligence 18 IOCs YARA 4 File information Comments

SHA256 hash: ae1a58b73c14de3d0d4af02ac0c136a4e804ed1a911de386fa40208672611309
SHA3-384 hash: 1628251640f801f8314882b1538a7c4344ee2ce4b043dd636a8806cc16f3545c4613152cdcd3e37be325ae79226d3dd7
SHA1 hash: ea709516603279a6513ab58ae93ce220f0f0210e
MD5 hash: bb80b31e43893a35fabbdca00c3fd55e
humanhash: mockingbird-autumn-west-beryllium
File name:TaxInvoiceMH1252.pdf.bat
Download: download sample
Signature RemcosRAT
File size:1'261'056 bytes
First seen:2026-07-14 06:55:19 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'245 x AgentTesla, 20'500 x Formbook, 12'374 x SnakeKeylogger)
ssdeep 24576:6xN6pbVwFbESb7mw/7T5Xald1sWNUcuNJPEfL0I++XpUXLlqhF:D1VcbxPms7TJqsWV8dEwW5U7l
Threatray 3'954 similar samples on MalwareBazaar
TLSH T157452208725AD60BC92227391E70F2B927BF1DE9B811D2169FDDFCCB7A62B459C041D2
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon 0000000000000000 (907 x AgentTesla, 573 x Formbook, 316 x RedLineStealer)
Reporter abuse_ch
Tags:bat exe RAT RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
203
Origin country :
SE SE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
keylog micro word
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
Connection attempt
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-14T01:53:00Z UTC
Last seen:
2026-07-16T04:46:00Z UTC
Hits:
~100
Result
Threat name:
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
Adds a directory exclusion to Windows Defender
AI detected malicious Powershell script
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Creates an autostart registry key pointing to binary in C:\Windows
Creates autostart registry keys with suspicious values (likely registry only malware)
Delayed program exit found
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Loading BitLocker PowerShell Module
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Suspicious powershell command line found
Unusual module load detection (module proxying)
Uses an obfuscated file name to hide its real file extension (double extension)
Yara detected AntiVM3
Yara detected Powershell decode and execute
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1941974 Sample: TaxInvoiceMH1252.pdf.bat.exe Startdate: 14/07/2026 Architecture: WINDOWS Score: 100 58 Found malware configuration 2->58 60 Malicious sample detected (through community Yara rule) 2->60 62 Multi AV Scanner detection for submitted file 2->62 64 15 other signatures 2->64 7 TaxInvoiceMH1252.pdf.bat.exe 1 7 2->7         started        11 powershell.exe 19 2->11         started        13 powershell.exe 2->13         started        15 svchost.exe 1 1 2->15         started        process3 dnsIp4 44 C:\Users\user\AppData\...\dllFVttXbgVQ.exe, PE32 7->44 dropped 46 C:\Users\...\dllFVttXbgVQ.exe:Zone.Identifier, ASCII 7->46 dropped 48 C:\Users\user\AppData\...\5zmgho0mipl.ps1, ASCII 7->48 dropped 50 C:\Users\...\TaxInvoiceMH1252.pdf.bat.exe.log, ASCII 7->50 dropped 80 Creates autostart registry keys with suspicious values (likely registry only malware) 7->80 82 Creates an autostart registry key pointing to binary in C:\Windows 7->82 84 Adds a directory exclusion to Windows Defender 7->84 86 Unusual module load detection (module proxying) 7->86 18 TaxInvoiceMH1252.pdf.bat.exe 2 3 7->18         started        23 powershell.exe 23 7->23         started        25 dllFVttXbgVQ.exe 3 11->25         started        27 conhost.exe 11->27         started        29 dllFVttXbgVQ.exe 2 13->29         started        31 conhost.exe 13->31         started        54 127.0.0.1 unknown unknown 15->54 file5 signatures6 process7 dnsIp8 52 213.152.162.21, 11525 GLOBALLAYERNL Netherlands 18->52 42 C:\ProgramData\vlc\logs.dat, data 18->42 dropped 66 Installs a global keyboard hook 18->66 68 Loading BitLocker PowerShell Module 23->68 33 conhost.exe 23->33         started        36 WmiPrvSE.exe 23->36         started        70 Multi AV Scanner detection for dropped file 25->70 72 Contains functionalty to change the wallpaper 25->72 74 Contains functionality to steal Chrome passwords or cookies 25->74 78 4 other signatures 25->78 38 dllFVttXbgVQ.exe 25->38         started        76 Injects a PE file into a foreign processes 29->76 40 dllFVttXbgVQ.exe 29->40         started        file9 signatures10 process11 signatures12 56 Installs a global keyboard hook 33->56
Verdict:
inconclusive
YARA:
5 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.29 Win 32 Exe x86
Threat name:
Win32.Spyware.Negasteal
Status:
Malicious
First seen:
2026-07-14 04:47:20 UTC
File Type:
PE (.Net Exe)
Extracted files:
9
AV detection:
28 of 38 (73.68%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:gst gtr discovery execution persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: Remcos
Malware Config
C2 Extraction:
213.152.162.21:11525
Unpacked files
SH256 hash:
ae1a58b73c14de3d0d4af02ac0c136a4e804ed1a911de386fa40208672611309
MD5 hash:
bb80b31e43893a35fabbdca00c3fd55e
SHA1 hash:
ea709516603279a6513ab58ae93ce220f0f0210e
SH256 hash:
dd4ddcb93d369da8437b8f8f1386fec6a5b18251c94e0911c38540bb9a9fa280
MD5 hash:
d5a49cd6b89e6063ba408f9bfceae073
SHA1 hash:
e27b970a099864abf9190a5b26894ffb1e58e271
SH256 hash:
8cfbbe2019d095644511694e9fcef8c38a1acf26fc47e97f5a6551f03a4635e5
MD5 hash:
4e142150825681951ee7798a70b58879
SHA1 hash:
e5deda3c68c017cf5b1596c51c682874ccc7548a
SH256 hash:
46b7f4dbc7c7168015a482d04d10c9685a3e203bc474d992eda99790b863a772
MD5 hash:
e610f1b52df2b85b229296e7760a46c7
SHA1 hash:
fd58ff52d9a49ac39ab1a379caa49b11bbb19b5e
Detections:
win_remcos_auto win_remcos_w0 Remcos
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments