🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e940b8b7a202521e1627074dae16f0edc7f1760632e962c92b5747cf18ff8d7a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 11


Intelligence 11 IOCs YARA 2 File information Comments

SHA256 hash: e940b8b7a202521e1627074dae16f0edc7f1760632e962c92b5747cf18ff8d7a
SHA3-384 hash: 2c90c916e918a27f3124bda84a72cb4ac212a067e3c4ddad7b18ae2b3ca123b6da818af0bb6a4a72404492dfc39d4cc3
SHA1 hash: f225f5c967addc039c4721b5ce64b204b6181fbe
MD5 hash: 8f35d30706a9a3f07b769308a9927e42
humanhash: florida-thirteen-early-two
File name:Bestellung.cmd
Download: download sample
Signature RemcosRAT
File size:1'912'823 bytes
First seen:2026-07-20 08:54:33 UTC
Last seen:Never
File type:cmd cmd
MIME type:text/x-msdos-batch
ssdeep 24576:34PCbMFJqtrlpknHwABmhb3hBuN8Eal2heOiGWb:xbMFik8rBuOgE7
TLSH T19895CF3B194B3FFF7B764E8692503A010F682D8B16456D4A39EC39A2EBDDD180F18539
Magika batch
Reporter lowmal3
Tags:cmd RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
94
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
BatchScript
Details
Verdict:
Malicious
Score:
92.5%
Tags:
dropper shell sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug base64 certutil cmd cscript evasive lolbin obfuscated packed
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-15T07:09:00Z UTC
Last seen:
2026-07-22T07:35:00Z UTC
Hits:
~1000
Result
Threat name:
Remcos, DonutLoader
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Command shell drops VBS files
Detected Remcos RAT
Drops PE files to the document folder of the user
Found malware configuration
Hides threads from debuggers
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Queries DNS domain through GetComputerNameExW (potential sandbox evasion)
Sigma detected: Remcos
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Unusual module load detection (module proxying)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected DonutLoader
Yara detected EXE embedded in BAT file
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1945104 Sample: Bestellung.cmd Startdate: 20/07/2026 Architecture: WINDOWS Score: 100 48 neuvo.ydns.eu 2->48 50 www.google.com 2->50 52 7 other IPs or domains 2->52 56 Found malware configuration 2->56 58 Malicious sample detected (through community Yara rule) 2->58 60 Antivirus detection for URL or domain 2->60 62 12 other signatures 2->62 11 cmd.exe 2 2->11         started        signatures3 process4 file5 44 C:\Users\user\AppData\Local\Temp\~run.vbs, ASCII 11->44 dropped 76 Command shell drops VBS files 11->76 15 cscript.exe 2 11->15         started        17 conhost.exe 11->17         started        19 cmd.exe 1 11->19         started        signatures6 process7 process8 21 cmd.exe 3 15->21         started        file9 42 C:\Users\user\...42CWSEUCULTTDXEPLFCDK.p1f, ASCII 21->42 dropped 24 NCWSEUCULTTDXEPLFCDK.p1f 4 1 21->24         started        28 certutil.exe 3 2 21->28         started        31 certutil.exe 2 21->31         started        33 conhost.exe 21->33         started        process10 dnsIp11 54 neuvo.ydns.eu 94.198.96.165, 49739, 62050 ASSEFLOWIT Italy 24->54 66 Detected Remcos RAT 24->66 68 Hides threads from debuggers 24->68 70 Unusual module load detection (module proxying) 24->70 35 cmd.exe 1 24->35         started        38 conhost.exe 24->38         started        46 C:\Users\...46CWSEUCULTTDXEPLFCDK.p1f.tmp, PE32 28->46 dropped 72 Drops PE files to the document folder of the user 28->72 74 Queries DNS domain through GetComputerNameExW (potential sandbox evasion) 28->74 file12 signatures13 process14 signatures15 64 Uses schtasks.exe or at.exe to add and modify task schedules 35->64 40 schtasks.exe 1 35->40         started        process16
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-07-15 14:47:39 UTC
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Executes a VBScript file via the Windows Script Host.
Suspicious use of NtSetInformationThreadHideFromDebugger
Deobfuscate/Decode Files or Information
Checks computer location settings
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:dgaaga
Author:Harshit
Description:Detects suspicious PowerShell or registry activity
Rule name:telebot_framework
Author:vietdx.mb

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

cmd cmd e940b8b7a202521e1627074dae16f0edc7f1760632e962c92b5747cf18ff8d7a

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments