81be5885ba8ef998066cd36efe6884fea44408ad663ea62666d973f800f9e63e
Classification: Malicious
81be5885ba8ef998066cd36efe6884fea44408ad663ea62666d973f800f9e63e is a malicious file sample. Linked to Remcos malware. Detected by 62 antivirus engines.
Detection summary
- 62 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 1 contacted hosts
- 1 DNS requests
MITRE ATT&CK associations
Malware families: REMCOS (S0332)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Hybrid-Analysis | 2026-09-02 17:45:05 | 2026-09-02 17:45:05 | malicious-activity | |
| Generic.Malware | MalwareBazaar Abuse.ch | 2024-10-11 15:24:17 | 2024-10-11 15:24:17 | malicious-activity | |
| RemcosRAT | MalwareBazaar Abuse.ch | 2024-10-11 15:24:17 | 2024-10-11 15:24:17 | malicious-activity | S0332 Remcos |
Sample information
- Filenames
- 81be5885ba8ef998066cd36efe6884fea44408ad663ea62666d973f800f9e63e, 172866025525495dd8e8afca3f3b56403378ef77acfe3af22ea24afc36e105013588df0d1b286.dat-decoded
- File type
- application/x-dosexec
- MD5
3ecad91b6dd833ebc34731f8f07341fa- SHA-1
dcc36f7bf54db788bea8feb31c8b6705bf7bb3dd- SHA-256
81be5885ba8ef998066cd36efe6884fea44408ad663ea62666d973f800f9e63e- First indexed
- 2024-10-11 16:19:22
- Last updated
- 2026-09-02 17:45:05
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Generic.Remcos.158B84BA |
| APEX | Malicious |
| AVG | Win32:RATX-gen [Trj] |
| AhnLab-V3 | Backdoor/Win.Remcos.R634199 |
| Alibaba | Backdoor:Win32/Remcos.4bd4e110 |
| Antiy-AVL | Trojan[Backdoor]/Win32.Rescoms.b |
| Arcabit | Generic.Remcos.158B84BA |
| Avast | Win32:RATX-gen [Trj] |
| Avira | BDS/Backdoor.Gen |
| Baidu | Win32.Trojan.Kryptik.awm |
| BitDefender | Generic.Remcos.158B84BA |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Backdoor.Remcos |
| CTX | exe.trojan.remcos |
| ClamAV | Win.Trojan.Remcos-9841897-0 |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | BackDoor.Remcos.438 |
| ESET-NOD32 | a variant of Win32/Rescoms.B |
| Elastic | Windows.Trojan.Remcos |
| Emsisoft | Generic.Remcos.158B84BA (B) |
| F-Secure | Backdoor.BDS/Backdoor.Gen |
| FireEye | Generic.mg.3ecad91b6dd833eb |
| Fortinet | W32/Rescoms.U!tr |
| GData | Generic.Remcos.158B84BA |
| Detected | |
| Gridinsoft | Backdoor.Win32.Remcos.sa |
| Ikarus | Backdoor.Remcos |
| Jiangmin | Backdoor.Remcos.dzw |
| K7AntiVirus | Trojan ( 0053ac2c1 ) |
| K7GW | Trojan ( 0053ac2c1 ) |
| Kaspersky | HEUR:Backdoor.Win32.Remcos.gen |
| Kingsoft | malware.kb.a.1000 |
| Lionic | Trojan.Win32.Remcos.m!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.121218.susgen |
| McAfeeD | Real Protect-LS!3ECAD91B6DD8 |
| MicroWorld-eScan | Generic.Remcos.158B84BA |
| Microsoft | Backdoor:Win32/Remcos.GA!MTB |
| NANO-Antivirus | Trojan.Win32.Rescoms.kqldxd |
| Paloalto | generic.ml |
| Panda | Trj/Genetic.gen |
| Rising | Backdoor.Remcos!1.BAC7 (CLASSIC) |
| SUPERAntiSpyware | Trojan.Agent/Gen-Crypt |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win32.Remcos.gh |
| Sophos | Mal/Remcos-B |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Trojan.Win32.Remcos.16001234 |
| VBA32 | BScope.Backdoor.Remcos |
| VIPRE | Generic.Remcos.158B84BA |
| Varist | W32/Trojan.TEVC-5559 |
| ViRobot | Trojan.Win.Z.Remcos.494592.ZH |
| VirIT | Trojan.Win32.Remcos.HCY |
| Webroot | W32.Trojan.Remcos |
| Zillya | Trojan.Rescoms.Win32.1913 |
| ZoneAlarm | HEUR:Backdoor.Win32.Remcos.gen |
| alibabacloud | Backdoor:Win/Remcos |
| huorong | Backdoor/Remcos.k |