MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b9801a5905c0fdb2ef2bef0708d88ba4887b6adbe19b832ad9952d820d3a69a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 4 File information Comments

SHA256 hash: b9801a5905c0fdb2ef2bef0708d88ba4887b6adbe19b832ad9952d820d3a69a2
SHA3-384 hash: ff78cda1a555b0a50f9a00462324fd3a7bcb8a1fdd59f0aef59581983e8c6640f9f6a861691671fc125cc2da9b11e243
SHA1 hash: 469c370f6afa5c095217d1c6ee6a0af0e63bf56b
MD5 hash: 7b93133c2cb6970e97010803564cd900
humanhash: virginia-stairway-monkey-carbon
File name:Sprogvidenskabsmandens.gz.zip
Download: download sample
Signature RemcosRAT
File size:28'823 bytes
First seen:2026-07-24 12:15:54 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:hS3w61vG5TQpwRw9ukOmzk29nq2/C28CVfpSC2zKUOVTl1HN59t+RVu0+kiIxgae:03e4ow9uQzvq0rpGKFPZ+ekDx5A2FLk
TLSH T146D2F164683380746976EBBA3C83790C78F537206BBE06B5F08D7DAC1B924E5077A547
Magika zip
Reporter TomU
Tags:RemcosRAT zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
CH CH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Sprogvidenskabsmandens.vbs
File size:56'137 bytes
SHA256 hash: 3a2ce5b01dc23cbe768df69bc04fcb4e68ee58f1341a767f0cbfd3cd15440a59
MD5 hash: 8090ffc96151a7b7cd83dd60d607f63c
MIME type:text/plain
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
anti-vm fingerprint
Verdict:
Malicious
File Type:
zip
First seen:
2026-07-07T22:03:00Z UTC
Last seen:
2026-07-20T23:56:00Z UTC
Hits:
~10
Verdict:
Malware
YARA:
2 match(es)
Tags:
T1059.005 WScript.Shell Zip Archive
Threat name:
Script-WScript.Trojan.Znyonm
Status:
Malicious
First seen:
2026-07-08 01:26:27 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
discovery execution
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Network Configuration Discovery: Internet Connection Discovery
Executes a VBScript file via the Windows Script Host.
Contacts third-party web service commonly abused for C2
Checks computer location settings
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:detect_tiny_vbs
Author:daniyyell
Description:Detects tiny VBS delivery technique
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip b9801a5905c0fdb2ef2bef0708d88ba4887b6adbe19b832ad9952d820d3a69a2

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments