f35b6cb6af991bfa735e039f6bc0e49c69759c015a207.exe
Classification: Malicious
f35b6cb6af991bfa735e039f6bc0e49c69759c015a207.exe is a malicious file sample. Linked to Remcos, Crossrat malware.
Detection summary
- 0 antivirus detections
- 2 IDS alerts
- 0 processes observed
- 2 contacted hosts
- 2 DNS requests
MITRE ATT&CK associations
Malware families: REMCOS (S0332) CROSSRAT (S0235)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| CrossRAT | ThreatFox Abuse.ch | 2026-07-10 14:54:45 | 2026-07-10 15:25:04 | S0235 CrossRAT | |
| RemcosRAT | MalwareBazaar Abuse.ch | 2026-07-10 03:10:16 | 2026-07-10 03:10:16 | malicious-activity | |
| Generic Malware | Hybrid-Analysis | 2026-07-09 20:45:04 | 2026-07-09 20:45:04 | malicious-activity | |
| Remcos | Triage | 2026-07-09 20:09:03 | 2026-07-09 20:09:03 | malicious-activity | S0332 Remcos |
Tags
infostealer suspicious windows-server-utility remcos flamengo discovery rat suricata jar.crossrat truptoSample information
- Filenames
- f35b6cb6af991bfa735e039f6bc0e49c69759c015a207.exe, f35b6cb6af991bfa735e039f6bc0e49c69759c015a2074b87eed8f20e4200135.exe, f35b6cb6af991bfa735e039f6bc0e49c69759c015a2074b87eed8f20e4200135.bin
- File type
- PE32 executable for MS Windows 5.01 (GUI), Intel i ...
- MD5
654607f31a256d943a2de9b63b30929c- SHA-1
679fb2dbfe81808a883729d15cd03b99eda8d1ba- SHA-256
f35b6cb6af991bfa735e039f6bc0e49c69759c015a2074b87eed8f20e4200135- First indexed
- 2026-07-09 20:09:03
- Last updated
- 2026-08-17 09:27:43