MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf24bb51af4d6c922bcb3eb46a712fef9cf3ed76822ebde5669a62673bf1d300. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 14


Intelligence 14 IOCs YARA 21 File information Comments

SHA256 hash: bf24bb51af4d6c922bcb3eb46a712fef9cf3ed76822ebde5669a62673bf1d300
SHA3-384 hash: b583db277b3fa97331973e6edd1ad5151de7dfba5d89e44b47ee15e7fa3693fad7063bc5ff60b38c201426103a5c3797
SHA1 hash: 83df1e5445c0fedb4cb356b5d6078b06ab7b3a59
MD5 hash: 0689d7f30f0bf15f1677685bc1b81763
humanhash: july-pluto-ack-timing
File name:bf24bb51af4d6c922bcb3eb46a712fef9cf3ed76822ebde5669a62673bf1d300
Download: download sample
Signature RemcosRAT
File size:872'448 bytes
First seen:2026-08-10 14:52:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 12288:hIQEk+Yxxltnn0gXuSNZz67fZ9q/sx6x5qPcIp35F44Ez9zMgX/+sp6PqA5RkTJb:X8Yp50WW7f314fqUItpm+snoOToxMN
TLSH T1A505F1641306DE46E0D68BF6B8B0E37432752DCFB9E2C3925FEA1FEB78193815554282
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
Reporter adrian__luca
Tags:exe RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Refund_ID - AA270526008009C.rar
Verdict:
No threats detected
Analysis date:
2026-07-27 06:06:23 UTC
Tags:
arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Gathering data
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Sending a TCP request to an infection source
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
entropy packed stealer
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-25T02:21:00Z UTC
Last seen:
2026-08-10T09:56:00Z UTC
Hits:
~1000
Gathering data
Gathering data
Threat name:
ByteCode-MSIL.Trojan.PureLogStealer
Status:
Malicious
First seen:
2026-07-25 06:02:43 UTC
File Type:
PE (.Net Exe)
Extracted files:
4
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:no-reply discovery execution persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: Remcos
Malware Config
C2 Extraction:
87.120.244.219:19601
Unpacked files
SH256 hash:
bf24bb51af4d6c922bcb3eb46a712fef9cf3ed76822ebde5669a62673bf1d300
MD5 hash:
0689d7f30f0bf15f1677685bc1b81763
SHA1 hash:
83df1e5445c0fedb4cb356b5d6078b06ab7b3a59
SH256 hash:
ff332e27e9756d76b430aa33921c07184405cac0047712e7e63fad5b3b03684b
MD5 hash:
a6e6a64e53f6f1a055264904d044c6f4
SHA1 hash:
37b602f4a4c94b608c51f588762db428054fcc28
SH256 hash:
232a1f5afae6e122203e29233594d10464fed1d7f44af578be14ba1030a8eccf
MD5 hash:
82d262a22a539ff209e8bb15a8458dae
SHA1 hash:
4393f31c8b490432ee7e8deb2883105d16a5094f
SH256 hash:
3ee66e86710cdaa7a28ba66eff2504f2fd4d0bd7cd9d726141aca66f1141080a
MD5 hash:
fdd8975943d3377b0992672e30a21b55
SHA1 hash:
49ac7062988e1cf38947c749d1e5e53ee4e50cde
Detections:
win_remcos_auto win_remcos_g0 Remcos
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CMD_Ping_Localhost
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:FreddyBearDropper
Author:Dwarozh Hoshiar
Description:Freddy Bear Dropper is dropping a malware through base63 encoded powershell scrip.
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_EventViewer
Author:ditekSHen
Description:detects Windows exceutables potentially bypassing UAC using eventvwr.exe
Rule name:malware_Remcos_strings
Author:JPCERT/CC Incident Response Group
Description:detect Remcos in memory
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:RAT_remcos_strings
Author:0x0d4y
Description:This rule detects the remcos through your specific strings.
Reference:Internal Research
Rule name:rat_win_remcos
Author:Sekoia.io
Description:DEPRECATED : Find Remcos RAT samples based on specific strings
Rule name:Remcos
Author:JPCERT/CC Incident Response Group
Description:detect Remcos in memory
Rule name:remcos_rat
Author:jeFF0Falltrades
Rule name:REMCOS_RAT_variants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.
Rule name:Windows_Generic_Threat_994f2330
Author:Elastic Security
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments