🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f88971f2b24f63bcb40e9a01ac8bc79850c9ea0410eb2f11ad5400cea34553da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 7


Intelligence 7 IOCs 1 YARA File information Comments

SHA256 hash: f88971f2b24f63bcb40e9a01ac8bc79850c9ea0410eb2f11ad5400cea34553da
SHA3-384 hash: b874c8f1326ac7cdb2f7dbeeb1f6f5a8aa6ad3a30fb2c451bb3232b30c781f4f739f41c72a8e34c80f7529f697833424
SHA1 hash: 809d4f1cf5789089919b8fbe15d6f6e8f0a80683
MD5 hash: 2c71b1a2da29ded2e9fae8f7f682c7b1
humanhash: spaghetti-happy-potato-hamper
File name:IMG-Bill - Ref#843993400 New GROUP BOOKING - SOA.r00
Download: download sample
Signature RemcosRAT
File size:1'873'137 bytes
First seen:2026-10-05 05:30:55 UTC
Last seen:Never
File type: r00
MIME type:application/vnd.rar
ssdeep 24576:digOv8FR1ONNC8JiMec7AdTAMqlb6EEoW5ApG/Ii4Lm0VwCk6bKyn8WgdDdzdMFc:JOvcOCy7Ad5qlWrT49iJCk6b6dDdzdMe
TLSH T1418533AD2BE74D951C706C2F8E4B9B7C48372CDFC5C8E953E199A8AA9E1720D52030DD
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter ppppt
Tags:r00 RemcosRAT

Indicators Of Compromise (IOCs)


Below is a list of indicators of compromise (IOCs) associated with this malware samples.

IOCThreatFox Reference
43.228.157.171:2404 https://threatfox.abuse.ch/ioc/1916607/

Intelligence


File Origin
# of uploads :
1
# of downloads :
80
Origin country :
TH TH
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:IMG-Bill - Ref#843993400 New GROUP BOOKING - SOA.JS
File size:4'714'282 bytes
SHA256 hash: 4784ee07a182d7300d16633c36938e32cecdf02a64121b4e5f7f97b0f48ce342
MD5 hash: a95040a14693c9473a4a5a7dc5c49771
MIME type:text/plain
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug dropper evasive obfuscated packed repaired
Verdict:
Malicious
File Type:
rar
First seen:
2026-10-05T03:40:00Z UTC
Last seen:
2026-10-05T03:46:00Z UTC
Hits:
~10
Threat name:
Win32.Downloader.ModiLdr
Status:
Malicious
First seen:
2026-10-05 05:31:22 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
14 of 38 (36.84%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

r00 f88971f2b24f63bcb40e9a01ac8bc79850c9ea0410eb2f11ad5400cea34553da

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments