MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 cd98f98f7fc5e22cd73e1513a3f879e0a9dc199ebc9dc856ae3e479b977f8bb6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 10
| SHA256 hash: | cd98f98f7fc5e22cd73e1513a3f879e0a9dc199ebc9dc856ae3e479b977f8bb6 |
|---|---|
| SHA3-384 hash: | 4aae1490a019c7d4d0f38a1f0cbaf66395109c49e6b4fa3f4152279f21be38cc94cb40d618599f29c73421b990d846b4 |
| SHA1 hash: | 78988ce4e23cf0c1da73e07c0577236560f7a0fc |
| MD5 hash: | b30794622fd0c86fba76bd43db610e96 |
| humanhash: | grey-crazy-fourteen-network |
| File name: | Shipping_Documents.vbs |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 23'457 bytes |
| First seen: | 2026-05-21 14:17:33 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | text/plain |
| ssdeep | 384:02917X61lSDpTRujCL5/97WboOaqvq3djfq3Mpkn2IxdoWX9tsYi:029lq2D3x8kOkhFeLzns3 |
| TLSH | T1ABB29760C5E13A94386756BD5CC43631A6B09BBB423101E9F1D8F218E80E6B87F7F98D |
| Magika | vba |
| Reporter | |
| Tags: | RemcosRAT vbs |
Intelligence
File Origin
# of uploads :
1
# of downloads :
43
Origin country :
CHVendor Threat Intelligence
No detections
Detection:
n/a
Verdict:
Malicious
Score:
70%
Tags:
shell sage
Verdict:
Likely Malicious
Threat level:
7.5/10
Confidence:
100%
Tags:
anti-vm fingerprint masquerade
Verdict:
Malicious
Labled as:
Trojan_Script_Wacatac_B_ml
Verdict:
Malicious
File Type:
vbs
First seen:
2026-05-20T14:32:00Z UTC
Last seen:
2026-05-23T11:57:00Z UTC
Hits:
~10000
Score:
99%
Verdict:
Malware
File Type:
SCRIPT
Gathering data
Detection:
remcos
Threat name:
Script-WScript.Backdoor.Remcos
Status:
Malicious
First seen:
2026-05-20 20:53:45 UTC
File Type:
Text (VBS)
AV detection:
10 of 36 (27.78%)
Threat level:
5/5
Detection(s):
Suspicious file
Result
Malware family:
n/a
Score:
8/10
Tags:
discovery persistence privilege_escalation
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Event Triggered Execution: Installer Packages
System Location Discovery: System Language Discovery
System Network Configuration Discovery: Internet Connection Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Contacts third-party web service commonly abused for C2
Checks computer location settings
Use of msiexec (install) with remote resource
Badlisted process makes network request
Malware family:
GuLoader
Verdict:
Malicious
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.