MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0149c0c3476c97e13ab5f4d656ad0b53ba45dea1b3f8fdaf51d0e4ef5db2aa9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 14


Intelligence 14 IOCs YARA 2 File information Comments

SHA256 hash: e0149c0c3476c97e13ab5f4d656ad0b53ba45dea1b3f8fdaf51d0e4ef5db2aa9
SHA3-384 hash: d32d3474a4ba881d383213fcbbe3b766219b79b2e1ec09cf38fb2b0e4d4030a628a224f75a930bd61377f80269a329e0
SHA1 hash: 3b8ca3a3b325fb1ddb13528422487abd169ddfc8
MD5 hash: c894799d11c657b5482c768edd4a693d
humanhash: monkey-saturn-happy-angel
File name:SecuriteInfo.com.Exploit.CVE-2017-11882.123.30451.5205
Download: download sample
Signature RemcosRAT
File size:462'848 bytes
First seen:2026-05-14 12:44:02 UTC
Last seen:Never
File type:Excel file xlsx
MIME type:application/vnd.ms-excel
ssdeep 3072:Dh8q9rWNXULqd+O13x6cwCLTVddNd3ECs9rWNXULqd+O13x6cwCLTOddNd3EGnCH:Dh859NdVfMNdvC0KR+VTOxN1NUV8G9
TLSH T1AEA46C7BF09CC5CEDB6782B1AB674900070EAD183B955626342F7A36F5B3E2CCA87045
TrID 34.0% (.XLS) Microsoft Excel sheet (32500/1/3)
29.3% (.XLS) Microsoft Excel sheet (alternate) (28000/1/3)
25.6% (.XLS) Microsoft Excel sheet (alternate) (24500/1/2)
8.3% (.) Generic OLE2 / Multistream Compound (8000/1)
2.6% (.ASSETS) Unity binary serialized Assets (generic) (2509/3/1)
Magika xls
Reporter SecuriteInfoCom
Tags:RemcosRAT xlsx

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE dump

MalwareBazaar was able to identify 26 sections in this file using oledump:

Section IDSection sizeSection name
1114 bytesCompObj
2244 bytesDocumentSummaryInformation
3200 bytesSummaryInformation
494 bytesMBD001785C0/CompObj
562 bytesMBD001785C0/Ole
693693 bytesMBD001785C0/CONTENTS
794 bytesMBD001785C1/CompObj
820 bytesMBD001785C1/Ole
953021 bytesMBD001785C1/CONTENTS
1094 bytesMBD001785C2/CompObj
1162 bytesMBD001785C2/Ole
1293693 bytesMBD001785C2/CONTENTS
1394 bytesMBD001785C3/CompObj
1420 bytesMBD001785C3/Ole
1553021 bytesMBD001785C3/CONTENTS
161627 bytesMBD001785C4/OLE10NatIve
1720 bytesMBD001785C4/Ole
18147328 bytesWorkbook
19525 bytes_VBA_PROJECT_CUR/PROJECT
20104 bytes_VBA_PROJECT_CUR/PROJECTwm
21977 bytes_VBA_PROJECT_CUR/VBA/Sheet1
22977 bytes_VBA_PROJECT_CUR/VBA/Sheet2
23977 bytes_VBA_PROJECT_CUR/VBA/Sheet3
24985 bytes_VBA_PROJECT_CUR/VBA/ThisWorkbook
252644 bytes_VBA_PROJECT_CUR/VBA/_VBA_PROJECT
26553 bytes_VBA_PROJECT_CUR/VBA/dir

Intelligence


File Origin
# of uploads :
1
# of downloads :
120
Origin country :
FR FR
Vendor Threat Intelligence
Malware configuration found for:
MSO
Details
MSO
extracted VBA Macros and, if observed, MS-OFORM variables/data are added to the knowledge base for usage in later parsing of the Macros
Malware family:
n/a
ID:
1
File name:
Orden No. 5700080331.xls
Verdict:
No threats detected
Analysis date:
2026-05-14 12:38:52 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Verdict:
Legit
File type:
application/vnd.openxmlformats-officedocument.spreadsheetml.sheet
Has a screenshot:
False
Contains macros:
False
Verdict:
Malicious
Score:
92.5%
Tags:
office micro macro
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Searching for synchronization primitives
Launching a process
DNS request
Creating a file in the %AppData% directory
Сreating synchronization primitives
Searching for the window
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Launching a service
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request to an infection source
Possible injection to a system process
Connection attempt by exploiting the app vulnerability
Connection attempt to an infection source
Bypassing of proactive protection methods using Windows Management Instrumentation (WMI)
Connection attempt to an infection source by exploiting the app vulnerability
Sending an HTTP GET request to an infection source by exploiting the app vulnerability
Sending a custom TCP request by exploiting the app vulnerability
Launching a process by exploiting the app vulnerability
Result
Verdict:
Malicious
File Type:
Legacy Excel File with Macro
Behaviour
BlacklistAPI detected
Document image
Document image
Label:
Malicious
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
0%
Verdict:
Malicious
File Type:
xls
First seen:
2026-05-14T05:14:00Z UTC
Last seen:
2026-05-16T10:24:00Z UTC
Hits:
~100
Verdict:
inconclusive
YARA:
6 match(es)
Tags:
Office Document
Threat name:
Win32.Exploit.CVE-2017-11882
Status:
Malicious
First seen:
2026-05-14 12:44:45 UTC
File Type:
Document
Extracted files:
61
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:informational_win_ole_protected
Author:Jeff White (karttoon@gmail.com) @noottrak
Description:Identify OLE Project protection within documents.
Rule name:XLS_STRINGS
Author:somedieyoungZZ
Description:Detect Strings targeting Bangladesh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments