🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fc655965ca5ea71fc16ea08b3ab021786d2720e4693b72a8e432d93740eb0987. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: fc655965ca5ea71fc16ea08b3ab021786d2720e4693b72a8e432d93740eb0987
SHA3-384 hash: c18d72f710af9029fc45bbb542b9e4fc1aa3b1625396992bc76443895e8e350946d8d55c9d844b8139d71c138904a9f6
SHA1 hash: 9b7d67ae58a501e8c3cfe94d56b43b73c9d6ce9d
MD5 hash: 7ff405701e8ee91dd0470332328bf676
humanhash: michigan-grey-apart-butter
File name:Salary Increase Notice for 2026.pdf.JS.JS
Download: download sample
Signature RemcosRAT
File size:12'817'929 bytes
First seen:2026-09-14 07:16:00 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 196608:RBcJ/NWwKeVz0FMNOYSE04mua43BodSR0Yqys:XcJ/NBLdRNOpE04K43QSR0Z
TLSH T16AD64B4C9854AA81A4BC0AD44E8F1FD5463D534FBF78A507B37C26991FB8B9332E9234
Magika txt
Reporter abuse_ch
Tags:js RAT RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
205
Origin country :
SE SE
Vendor Threat Intelligence
No detections
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
obfuscated repaired
Verdict:
Malicious
File Type:
js
First seen:
2026-09-13T20:37:00Z UTC
Last seen:
2026-09-14T04:03:00Z UTC
Hits:
~10
Result
Threat name:
n/a
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Found potential dummy code loops (likely to delay analysis)
Multi AV Scanner detection for submitted file
Sigma detected: WScript or CScript Dropper
Uses an obfuscated file name to hide its real file extension (double extension)
Behaviour
Behavior Graph:
Gathering data
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-14 01:07:17 UTC
File Type:
Text (JavaScript)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
donutloader
Score:
  10/10
Tags:
family:donutloader execution loader
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: JavaScript
Enumerates physical storage devices
Checks computer location settings
Executes dropped EXE
Detects DonutLoader
Family: DonutLoader
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments