MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 12


Intelligence 12 IOCs YARA File information Comments

SHA256 hash: c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a
SHA3-384 hash: 2fc182b580e7651bc61c20270fd2e751e77b0a290f82943486cadab7aa16fee899287416e65d007a79634759928cb077
SHA1 hash: f30db4c7e2a0d696528d3a193a8ab6aac2911bf8
MD5 hash: 015ca6dc0327be60d7ee89b2c92fd1fb
humanhash: mirror-island-robert-pluto
File name:SecuriteInfo.com.Variant.Stealer.565.85346354
Download: download sample
Signature RemusStealer
File size:224'768 bytes
First seen:2026-07-04 07:33:41 UTC
Last seen:2026-07-04 08:37:41 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 20f35ed688f00eacb2c7ea603d9f248e (6 x RemusStealer)
ssdeep 3072:9SziFM0L3isiMJbXeEyqAbAMym8D68pnqWrrorGkM54YqV:cilJjOvB8DHAWH8HYq
TLSH T14424192BD25375FCE552C03852667232BB32BA3D47309EF70392D7359D21AC0AE79A25
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter SecuriteInfoCom
Tags:exe RemusStealer

Intelligence


File Origin
# of uploads :
2
# of downloads :
144
Origin country :
FR FR
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
SecuriteInfo.com.Variant.Stealer.565.85346354.exe
Verdict:
No threats detected
Analysis date:
2026-07-04 07:37:16 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Malicious
Score:
93.3%
Tags:
infosteal virus
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
adaptive-context fingerprint
Verdict:
Malicious
File Type:
exe x64
First seen:
2026-07-02T21:11:00Z UTC
Last seen:
2026-07-05T19:35:00Z UTC
Hits:
~10
Detections:
Trojan.Win32.Agent.gen
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Lazy
Status:
Malicious
First seen:
2026-07-02 23:53:54 UTC
File Type:
PE+ (Exe)
AV detection:
26 of 38 (68.42%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Similar samples:
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:remus_stealer discovery spyware stealer
Behaviour
Suspicious behavior: EnumeratesProcesses
Browser Information Discovery
Accesses cryptocurrency files/wallets, possible credential harvesting
Checks installed software on the system
Reads user/profile data of local email clients
Reads user/profile data of web browsers
Malware Config
C2 Extraction:
http://midpfv.xyz:9549
http://myrtler.biz:9549
http://carogra.biz:4219
Unpacked files
SH256 hash:
c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a
MD5 hash:
015ca6dc0327be60d7ee89b2c92fd1fb
SHA1 hash:
f30db4c7e2a0d696528d3a193a8ab6aac2911bf8
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemusStealer

Executable exe c82df76eec8d28b99a294bc174433851aad21df208a7f27038bc3fd5af91db3a

(this sample)

  
Delivery method
Distributed via web download

Comments