MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3c023cc4dd7a59b9dbd9e0e352d82d3b8a8fba0da89a47805693c0d482c184d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 11


Intelligence 11 IOCs YARA 13 File information Comments

SHA256 hash: b3c023cc4dd7a59b9dbd9e0e352d82d3b8a8fba0da89a47805693c0d482c184d
SHA3-384 hash: cff01e8b93cd920cbd50dcab647b36c63874a9a188738278f183a90705e74a74464733391c98adfaa03b6cbbbe79fb5b
SHA1 hash: 9719182a9d538417e43d34fe420baee08b723037
MD5 hash: f3ac3bb5adc82794b1430929dad5f6d6
humanhash: east-wolfram-shade-juliet
File name:Setup.exe
Download: download sample
Signature RemusStealer
File size:5'181'611 bytes
First seen:2026-08-25 20:44:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 2057790ae7855765d51bdc4142e62f9c (80 x RemusStealer, 5 x ValleyRAT, 5 x SalatStealer)
ssdeep 98304:06IDxUZKdU9XRN6xVcGTFK0QxzVAVrky8YeGUThH62UH3lsW5CVbJNDEuy0u6:0LxbU9XX6QQYlzVAVrkygdTGXlYrEug6
TLSH T1EF362304ABA1316AFCB39674CEB3C6E1DA313C46435196EB27E4645B0EFB1D1CB2A711
TrID 93.7% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39)
2.3% (.EXE) Win64 Executable (generic) (6522/11/2)
1.7% (.EXE) Win16 NE executable (generic) (5038/12/1)
0.7% (.EXE) OS/2 Executable (generic) (2029/13)
0.7% (.EXE) Generic Win/DOS Executable (2002/3)
Magika pebin
dhash icon 9494b494d4aeaeac (914 x DCRat, 486 x NirCmd, 172 x RedLineStealer)
Reporter aachum
Tags:37-187-155-230 ClickFraud exe gcleaner RemusStealer sfx Stealc unluckytool-com


Avatar
iamaachum
https://winds11.site/aa/Setup.rar

Stealc C2:
37.187.155.230
GCleaner C2:
185.156.73.98

Intelligence


File Origin
# of uploads :
1
# of downloads :
114
Origin country :
ES ES
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for the window
Сreating synchronization primitives
Searching for synchronization primitives
Creating a file
Creating a process from a recently created file
Creating a process with a hidden window
Connection attempt
Creating a file in the %temp% subdirectories
Launching a process
Deleting a recently created file
DNS request
Sending a custom TCP request
Changing a file
Sending an HTTP GET request
Unauthorized injection to a recently created process
Unauthorized injection to a system process
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug cmd fingerprint golang installer installer installer-heuristic large-file lolbin microsoft_visual_cc msbuild obfuscated overlay packed packed powershell reconnaissance sfx
Result
Threat name:
GCleaner, REMUS Stealer, Stealc
Detection:
malicious
Classification:
phis.troj.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
.NET source code contains very large strings
AI detected malicious page (phishing or scam)
Allocates memory in foreign processes
Bypasses PowerShell execution policy
C2 URLs / IPs found in malware configuration
Detected unpacking (creates a PE file in dynamic memory)
Drops large PE files
Found malware configuration
Found stalling execution ending in API Sleep call
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious webpage
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Potentially malicious time measurement code found
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Silenttrinity Stager Msbuild Activity
Sigma detected: WScript or CScript Dropper
Suricata IDS alerts for network traffic
Suspicious execution chain found
Suspicious powershell command line found
Unusual module load detection (module proxying)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
WScript reads language and country specific registry keys (likely country aware script)
Wscript starts Powershell (via cmd or directly)
Yara detected AntiVM3
Yara detected GCleaner
Yara detected REMUS Stealer
Yara detected Stealc
Yara detected Stealc v2
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1963699 Sample: Setup.exe Startdate: 25/08/2026 Architecture: WINDOWS Score: 100 53 45.91.200.135 PODAONLV Netherlands 2->53 55 185.156.73.98 FDN3UA Netherlands 2->55 57 10 other IPs or domains 2->57 73 Suricata IDS alerts for network traffic 2->73 75 Found malware configuration 2->75 77 Multi AV Scanner detection for submitted file 2->77 79 13 other signatures 2->79 10 Setup.exe 3 9 2->10         started        signatures3 process4 file5 45 C:\Users\user\Desktop\file.exe, PE32+ 10->45 dropped 47 C:\Users\user\Desktop\ae_mixtwo_2.exe, PE32 10->47 dropped 49 C:\Users\user\Desktop\OpenLink.ps1, ASCII 10->49 dropped 91 Drops large PE files 10->91 14 ae_mixtwo_2.exe 10 10->14         started        18 wscript.exe 1 10->18         started        20 file.exe 12 10->20         started        signatures6 process7 dnsIp8 51 C:\Users\user\AppData\Local\Temp\...\re21.exe, PE32+ 14->51 dropped 93 Multi AV Scanner detection for dropped file 14->93 95 Writes to foreign memory regions 14->95 97 Allocates memory in foreign processes 14->97 99 Injects a PE file into a foreign processes 14->99 23 re21.exe 14->23         started        26 MSBuild.exe 12 14->26         started        101 Suspicious powershell command line found 18->101 103 Wscript starts Powershell (via cmd or directly) 18->103 105 Bypasses PowerShell execution policy 18->105 113 3 other signatures 18->113 29 powershell.exe 23 18->29         started        61 37.187.155.230, 80 OVHFR France 20->61 107 Detected unpacking (creates a PE file in dynamic memory) 20->107 109 Unusual module load detection (module proxying) 20->109 111 Potentially malicious time measurement code found 20->111 file9 signatures10 process11 dnsIp12 81 Multi AV Scanner detection for dropped file 23->81 83 Modifies the context of a thread in another process (thread injection) 23->83 85 Injects a PE file into a foreign processes 23->85 31 MSBuild.exe 23->31         started        69 91.92.242.236, 49786, 80 OMEGATECH-ASSC Netherlands 26->69 71 drive.usercontent.google.com 142.251.211.97, 443, 49784 GOOGLE-GoogleLLCUS United States 26->71 87 Found stalling execution ending in API Sleep call 26->87 89 Unusual module load detection (module proxying) 26->89 34 chrome.exe 1 29->34         started        37 conhost.exe 29->37         started        signatures13 process14 dnsIp15 115 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 31->115 117 Unusual module load detection (module proxying) 31->117 59 192.168.2.5, 138, 443, 49580 unknown unknown 34->59 39 chrome.exe 34->39         started        signatures16 process17 dnsIp18 63 dl.google.com 142.250.188.14, 443, 49788 GOOGLE-GoogleLLCUS United States 39->63 65 android.l.google.com 142.250.65.78, 443, 49780, 49781 GOOGLE-GoogleLLCUS United States 39->65 67 5 other IPs or domains 39->67 43 Chrome Cache Entry: 244, PDP-11 39->43 dropped file19
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
.Net Executable Managed .NET PDB Path PE (Portable Executable) PE File Layout SOS: 0.20 SOS: 0.21 SOS: 0.92 Win 64 Exe x64
Gathering data
Result
Malware family:
gcleaner
Score:
  10/10
Tags:
family:gcleaner discovery execution loader
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies data under HKEY_USERS
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: NtCreateUserProcessBlockNonMicrosoftBinary
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of WriteProcessMemory
Browser Information Discovery
Enumerates physical storage devices
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
System Time Discovery
Drops file in Program Files directory
Drops file in Windows directory
Executes a VBScript file via the Windows Script Host.
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Downloads MZ/PE file
Family: GCleaner
Malware Config
C2 Extraction:
185.156.73.98
45.91.200.135
Dropper Extraction:
https://wappingerbicornshaps.com/s4r7aa2f7f74b7ac2ab0af7589004c3a8ef07971edb98
Unpacked files
SH256 hash:
b3c023cc4dd7a59b9dbd9e0e352d82d3b8a8fba0da89a47805693c0d482c184d
MD5 hash:
f3ac3bb5adc82794b1430929dad5f6d6
SHA1 hash:
9719182a9d538417e43d34fe420baee08b723037
SH256 hash:
b3e188bf57cbc7a25832ea1623180c43508e31c9dfcd50c914b42954d6dd8ca9
MD5 hash:
3887291cd322703465aeb5a65f43eee7
SHA1 hash:
bf9592a2d325f2202869f067d54b9375eba1f378
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SelfExtractingRAR
Author:Xavier Mertens
Description:Detects an SFX archive with automatic script execution
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemusStealer

Executable exe b3c023cc4dd7a59b9dbd9e0e352d82d3b8a8fba0da89a47805693c0d482c184d

(this sample)

  
Delivery method
Distributed via web download

Comments