MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 21
| SHA256 hash: | f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd |
|---|---|
| SHA3-384 hash: | 2994ff3349d2303c19253fe2dd4e19c1a87cd67bd935b3f5f41a3a1ee7fa4763b2e2001c69268ec9d8ce98f4ab3bac60 |
| SHA1 hash: | 6d2c4dec7124013ede8472a8cc4af34dff96f2f7 |
| MD5 hash: | c2c4fcaa0b2a62e71056e0d4f7411f9d |
| humanhash: | oklahoma-salami-black-jig |
| File name: | Q 094 -06 FMC-26 Supply 13 58 5K 11 10K - EBEN-1X.com |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'343'488 bytes |
| First seen: | 2026-07-02 16:15:30 UTC |
| Last seen: | 2026-08-10 13:35:25 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (49'192 x AgentTesla, 20'341 x Formbook, 12'364 x SnakeKeylogger) |
| ssdeep | 24576:ja6UwZel6gjdS1AWlTePMrP99wVWjy1TvPCL0k:ja69ZQ6ISuqB9iTvPX |
| TLSH | T12055021026EEDA01E4B64FB80872D2B01BB77D996931E20A4EEC3DDFB777B415814792 |
| TrID | 73.9% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 6.6% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.6% (.EXE) Win64 Executable (generic) (6522/11/2) 4.5% (.EXE) Win32 Executable (generic) (4504/4/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| Magika | pebin |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
CHVendor Threat Intelligence
Details
Result
Behaviour
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
902f94d7819fa6a65e9ba1d491e8fc7cb3d2bcb15ae1e4a89a065223d815f9f8
32b41325b3423e09831580aaaec166351b1e16c5e417ab7b5ad10ea60ba7dc9c
f37d19918ca9a92945198b23ab4e10be7d681e4aa1f8dfd1b0905482a006e7dd
86a9d7bbfd120217bd27921cdf336aef9d11ab5c1b2d4a247cbff4f2968e0c4a
d0ff391430324299558df195411ca64cfd19e235aa3df5e76732571d7fcb2210
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | NET |
|---|---|
| Author: | malware-lu |
| Rule name: | NETexecutableMicrosoft |
|---|---|
| Author: | malware-lu |
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.