MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d33682b92ddee2be9ab8dce71d6940cf17084571a869cf3e6cebe2f8a41137ef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemusStealer


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: d33682b92ddee2be9ab8dce71d6940cf17084571a869cf3e6cebe2f8a41137ef
SHA3-384 hash: b090fbd2add2c099d95d1b5cd29887b03cd7aae4e80ba4385aaddf36f9218fd3cd8961846da8762deb55b16c1a3e80ca
SHA1 hash: f2eed6018f5e1bc8dbbf9145e6b24395e952ddc9
MD5 hash: 356da0ec0a8ee0dbbce0a40f84b960a9
humanhash: kilo-twelve-bulldog-virginia
File name:d33682b92ddee2be9ab8dce71d6940cf17084571a869cf3e6cebe2f8a41137ef
Download: download sample
Signature RemusStealer
File size:224'256 bytes
First seen:2026-07-23 13:29:15 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 17081ce96f78327d576e14ddd5592fba (8 x RemusStealer)
ssdeep 3072:IKfPZ5SQdMDqhf6h8Yv50xTXa84P/UKydVnGGOV80QIS6MtWGaTNcAzU/zb:XJYWPrnJwQI2ccAz
TLSH T1A324396BD25330FCD552C078826A7232B772BA3D47249EF743A3C7369E219C06E79925
TrID 51.9% (.EXE) Win64 Executable (generic) (6522/11/2)
16.1% (.EXE) OS/2 Executable (generic) (2029/13)
15.9% (.EXE) Generic Win/DOS Executable (2002/3)
15.9% (.EXE) DOS Executable (generic) (2000/1)
Magika pebin
Reporter JAMESWT_WT
Tags:exe hairkeratin-net RemusStealer

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
IT IT
Vendor Threat Intelligence
No detections
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Using the Windows Management Instrumentation requests
DNS request
Connection attempt
Sending a custom TCP request
Connection attempt to an infection source
Query of malicious DNS domain
Verdict:
Unknown
File Type:
exe x64
First seen:
2026-06-24T11:58:00Z UTC
Last seen:
2026-07-24T11:30:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
4 match(es)
Tags:
Executable PE (Portable Executable) PE File Layout Win 64 Exe x64
Threat name:
Win64.Trojan.Remus
Status:
Malicious
First seen:
2026-06-26 10:09:46 UTC
File Type:
PE+ (Exe)
AV detection:
29 of 36 (80.56%)
Threat level:
  5/5
Result
Malware family:
remus_stealer
Score:
  10/10
Tags:
family:remus_stealer stealer
Malware Config
C2 Extraction:
http://hairkeratin.net:4959
http://carogra.biz:4219
http://myrtler.biz:9549
Unpacked files
SH256 hash:
d33682b92ddee2be9ab8dce71d6940cf17084571a869cf3e6cebe2f8a41137ef
MD5 hash:
356da0ec0a8ee0dbbce0a40f84b960a9
SHA1 hash:
f2eed6018f5e1bc8dbbf9145e6b24395e952ddc9
Detections:
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments