MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 be2142e2818d4df10efca8b223a823dae8dbcc0679e8e19a94fa9ae729c34273. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 22
| SHA256 hash: | be2142e2818d4df10efca8b223a823dae8dbcc0679e8e19a94fa9ae729c34273 |
|---|---|
| SHA3-384 hash: | 5680e0d8ae08de1eb80ffda2b3e8efed07d5873da8a0d1c9710b9f628bb74aa9e47b139fb2fe61b771f795273279bf7b |
| SHA1 hash: | 23847f095c29771561f5f8a8ef5b5ac880bc7595 |
| MD5 hash: | ed1859c564eaabbf87e31f620a8f265c |
| humanhash: | mobile-nevada-beer-six |
| File name: | fiyat istegi109743110602407178699-10245630286.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'320'456 bytes |
| First seen: | 2026-01-19 10:30:09 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'819 x AgentTesla, 19'743 x Formbook, 12'286 x SnakeKeylogger) |
| ssdeep | 24576:yu2mFCnFLoEfxoTBTZNmQH0Yi8jPPC521fTNDmbmcV09rv22:yHmFCFLoMxoZGDY7S5qfTpXc+9rv5 |
| Threatray | 1'259 similar samples on MalwareBazaar |
| TLSH | T1D85512547FA8CE12CC820BF14561E3751BBC6DE9E920D3474EEAACEF3874B261D48256 |
| TrID | 35.4% (.EXE) Win64 Executable (generic) (10522/11/4) 22.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.1% (.EXE) Win32 Executable (generic) (4504/4/1) 6.9% (.ICL) Windows Icons Library (generic) (2059/9) 6.8% (.EXE) OS/2 Executable (generic) (2029/13) |
| Magika | pebin |
| Reporter | |
| Tags: | exe RAT RemcosRAT |
Indicators Of Compromise (IOCs)
Below is a list of indicators of compromise (IOCs) associated with this malware samples.
| IOC | ThreatFox Reference |
|---|---|
| 91.92.242.99:2404 | https://threatfox.abuse.ch/ioc/1734318/ |
Intelligence
File Origin
NLVendor Threat Intelligence
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
91.92.242.99:2404
Unpacked files
be2142e2818d4df10efca8b223a823dae8dbcc0679e8e19a94fa9ae729c34273
1e0bbcaa4d9b3f4c144e10dad6fb9ecbde607e3c48c2d3194195f56852ef8ffb
3e4a68bdf48f606bad0af48e31d1776d5f5b82574d39cc320445f862d463a063
0249b099e5cf161407b30450caa1c6c778180293c336ac5990a7711cb4019ce5
ba1473e8daf2c65a904ab244102c92a49938f34af94502b920ca2d324c1f3017
ceaa3016ce3897c17e580b58f2a41cc247de57bada3271b30aa389bcf3787ea0
d1c9c2f4cfd087b3eb5d7ece5b4a9111c494bc34217b4d60ab85beba1a36e082
5f1454b656526752df4f393b86fd3fa41446cb486d7781fc96957c2849d69e8b
50681a74fd565805b9fa7d22dcb00ff4578b6821cdefb8c4d0f0da619f5621ca
f75cdb38544336db1eea1ccb9ddb99e1584dbae702986f1321d35825e08ef4d9
bf46723d199408eb636dfbb7d50ef97fad7c96be7aedca35fa350c92a7492a4e
5f947957f8b2c4cc8609167eaec826c9855e15c55dac3926c33b2a0c003cf773
19126fee5cfe21a6ac12f8aad59bbb83610c1c2971bde33d3a6c789e3a4952bc
df20937ff3543e699ba6abdbd74e74e276dc8bfab9fb5cad1927292541887f7c
2944010e5dc27c32e209f1aa2f0e9fb2ba05e90acb0beaccf16622b31389a349
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | INDICATOR_KB_CERT_7c1118cbbadc95da3752c46e47a27438 |
|---|---|
| Author: | ditekSHen |
| Description: | Detects executables signed with stolen, revoked or invalid certificates |
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | PE_Digital_Certificate |
|---|---|
| Author: | albertzsigovits |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.