MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcba0fe71c7ad69e5218d4934349a9da4d02b93eb30a8d62a58dfcedd299f6ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 15


Intelligence 15 IOCs YARA 5 File information Comments

SHA256 hash: dcba0fe71c7ad69e5218d4934349a9da4d02b93eb30a8d62a58dfcedd299f6ab
SHA3-384 hash: c53b2baa64030e31e2bf7d795bb3f579098ef327b71770ec5d3ba0baab61d6a707a17fb8894f09a5ac183bb4285493ea
SHA1 hash: dc0d0b953a2ae3f466cb3f3510ca1442a402be9a
MD5 hash: 4ccd20c59e7cd09fe1d45f8d7d2568af
humanhash: nuts-lactose-north-dakota
File name:dcba0fe71c7ad69e5218d4934349a9da4d02b93eb30a8d62a58dfcedd299f6ab
Download: download sample
Signature RemcosRAT
File size:1'422'848 bytes
First seen:2026-08-10 14:16:30 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (49'190 x AgentTesla, 20'337 x Formbook, 12'364 x SnakeKeylogger)
ssdeep 24576:4V/ubq60yxQaYYGx22ZJCdx00CG/l4RthO5IpA1ndunAkO/29RVdeu7ZevPYaHEC:LAyxZJAZJMx007KRXO5IpArVyVdeu4Yv
TLSH T1E1651264B714D122C6852B7C5AE5F23652E92DEEB911D302AFEDBCEF7925F010D08683
TrID 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.6% (.EXE) Win64 Executable (generic) (6522/11/2)
4.5% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Magika pebin
dhash icon e09a981c04820182 (4 x Formbook, 4 x AgentTesla, 1 x PhantomStealer)
Reporter adrian__luca
Tags:exe RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
HU HU
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
QuarantineMessage.zip
Verdict:
Malicious activity
Analysis date:
2026-07-13 11:55:33 UTC
Tags:
attachments attc-arch qrcode arch-exec

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a process with a hidden window
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a file in the %temp% directory
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
Enabling autorun with the standard Software\Microsoft\Windows\CurrentVersion\Run registry branch
Connection attempt to an infection source
Adding an exclusion to Microsoft Defender
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
crypt explorer krypt lolbin packed vbnet
Verdict:
Malicious
File Type:
exe x32
First seen:
2026-07-13T01:29:00Z UTC
Last seen:
2026-08-10T10:57:00Z UTC
Hits:
~1000
Gathering data
Threat name:
Win32.Backdoor.FormBook
Status:
Malicious
First seen:
2026-07-13 04:26:49 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
28 of 36 (77.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:gst gtr discovery execution persistence rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Suspicious use of SetThreadContext
Adds Run key to start application
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Family: Remcos
Malware Config
C2 Extraction:
213.152.162.21:11525
Unpacked files
SH256 hash:
dcba0fe71c7ad69e5218d4934349a9da4d02b93eb30a8d62a58dfcedd299f6ab
MD5 hash:
4ccd20c59e7cd09fe1d45f8d7d2568af
SHA1 hash:
dc0d0b953a2ae3f466cb3f3510ca1442a402be9a
SH256 hash:
7a09d4c71af5d34d449fc0ba91c8993492828bc5d6a1a3300c3f27df63c56e28
MD5 hash:
acbdef84097e8e77e2fa56219b88e479
SHA1 hash:
1d0de023f006931d010e601ff392b6621279ddba
SH256 hash:
ddf45303c8b64c0c76234ef1b46b79a44d6e596d43c9f235beaf8c5c73c9378f
MD5 hash:
ec11448554ae4c9fc0c5165d3ec87d7a
SHA1 hash:
d579a42c91bfe1b27289defc712a7a596f6874cc
SH256 hash:
46b7f4dbc7c7168015a482d04d10c9685a3e203bc474d992eda99790b863a772
MD5 hash:
e610f1b52df2b85b229296e7760a46c7
SHA1 hash:
fd58ff52d9a49ac39ab1a379caa49b11bbb19b5e
Detections:
win_remcos_auto win_remcos_w0 Remcos
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:test_rule_vldslv

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments