557551f8468b55e64af8969e71f9246f

Hash

  • MD5: 557551f8468b55e64af8969e71f9246f
  • SHA1: 2eaefd5a62a3a0d0181f1bee5a5aa0979fa51cf4
  • SHA256: 710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8
  • First Seen: 2026-05-22
  • Last Seen: 2026-05-22
Shortcuts: Hybrid Analysis MalwareBazaar Virustotal

Additional Information

MalwareBazaar
                {
    "query_status": "ok",
    "data": [
        {
            "sha256_hash": "710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8",
            "sha3_384_hash": "60c050ab98af175e91765fdc1e5391dbaee083119bc7f9c91a783f3fd00ed4fa5f0877639cfbd0734fa8dea3878a043e",
            "sha1_hash": "2eaefd5a62a3a0d0181f1bee5a5aa0979fa51cf4",
            "md5_hash": "557551f8468b55e64af8969e71f9246f",
            "first_seen": "2026-05-22 15:48:22",
            "last_seen": null,
            "file_name": "remotepe_2024-05-11_710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8.bin",
            "file_size": 528896,
            "file_type_mime": "application/x-dosexec",
            "file_type": "exe",
            "file_format": "PE",
            "file_arch": "AMD64",
            "reporter": "foxit_srt",
            "origin_country": "NL",
            "anonymous": 0,
            "signature": "Lazarus",
            "imphash": "3782d1d7433649d874912748e12d55d5",
            "tlsh": "T162B4394AF6B513F5D4BAC1388993652BFA7174A603709BCB53D04A6B1F23BE0A53E740",
            "telfhash": null,
            "gimphash": null,
            "ssdeep": "12288:9MD3GunM7dSTk4orbeK0dPj/BTSQyQSn+E:98dnHk4O/8VTH6+E",
            "magika": "pebin",
            "dhash_icon": null,
            "trid": [
                "37.0% (.EXE) Win64 Executable (generic) (6522/11/2)",
                "28.6% (.EXE) Win16 NE executable (generic) (5038/12/1)",
                "11.5% (.EXE) OS/2 Executable (generic) (2029/13)",
                "11.3% (.EXE) Generic Win/DOS Executable (2002/3)",
                "11.3% (.EXE) DOS Executable (generic) (2000/1)"
            ],
            "comment": null,
            "archive_pw": null,
            "tags": [
                "exe",
                "Lazarus",
                "RemotePE"
            ],
            "code_sign": null,
            "delivery_method": null,
            "intelligence": {
                "clamav": null,
                "downloads": "131",
                "uploads": "1",
                "mail": null
            },
            "file_information": [
                {
                    "context": "links",
                    "value": "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
                },
                {
                    "context": "cape",
                    "value": "https://www.capesandbox.com/analysis/67562/"
                }
            ],
            "ole_information": [],
            "yara_rules": [
                {
                    "rule_name": "cobalt_strike_tmp01925d3f",
                    "author": "The DFIR Report",
                    "description": "files - file ~tmp01925d3f.exe",
                    "reference": "https://thedfirreport.com"
                },
                {
                    "rule_name": "DebuggerCheck__API",
                    "author": null,
                    "description": null,
                    "reference": "https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara"
                },
                {
                    "rule_name": "DebuggerCheck__QueryInfo",
                    "author": null,
                    "description": null,
                    "reference": "https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara"
                },
                {
                    "rule_name": "dgaagas",
                    "author": "Harshit",
                    "description": "Uses certutil.exe to download a file named test.txt",
                    "reference": null
                },
                {
                    "rule_name": "golang_bin_JCorn_CSC846",
                    "author": "Justin Cornwell",
                    "description": "CSC-846 Golang detection ruleset",
                    "reference": null
                },
                {
                    "rule_name": "pe_detect_tls_callbacks",
                    "author": null,
                    "description": null,
                    "reference": null
                },
                {
                    "rule_name": "VECT_Ransomware",
                    "author": "Mustafa Bakhit",
                    "description": "Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.",
                    "reference": null
                }
            ],
            "vendor_intel": {
                "CERT-PL_MWDB": {
                    "detection": null,
                    "link": "https://mwdb.cert.pl/sample/710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8/"
                },
                "YOROI_YOMI": {
                    "detection": "Malicious File",
                    "score": "1.00"
                },
                "vxCube": {
                    "verdict": "clean1",
                    "maliciousness": "0",
                    "behaviour": []
                },
                "Intezer": {
                    "verdict": "unknown",
                    "family_name": null,
                    "analysis_url": "https://analyze.intezer.com/analyses/76906a41-f54f-4b3f-b854-27fdd6a5bce5?utm_source=MalwareBazaar"
                },
                "CAPE": {
                    "detection": null,
                    "link": "https://www.capesandbox.com/analysis/67562/"
                },
                "Triage": {
                    "malware_family": null,
                    "score": "3",
                    "link": "https://tria.ge/reports/260522-s82fjaax7w/",
                    "tags": [],
                    "signatures": [],
                    "malware_config": []
                },
                "ReversingLabs": {
                    "threat_name": "Win64.Trojan.Generic",
                    "status": "SUSPICIOUS",
                    "first_seen": "2026-05-22 15:49:21",
                    "scanner_count": "24",
                    "scanner_match": "10",
                    "scanner_percent": "41.67"
                },
                "Spamhaus_HBL": [
                    {
                        "detection": "suspicious",
                        "link": "https://www.spamhaus.org/hbl/"
                    }
                ],
                "UnpacMe": [
                    {
                        "sha256_hash": "710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8",
                        "md5_hash": "557551f8468b55e64af8969e71f9246f",
                        "sha1_hash": "2eaefd5a62a3a0d0181f1bee5a5aa0979fa51cf4",
                        "detections": [],
                        "link": "https://www.unpac.me/results/0ef836cf-5163-453e-b128-84d1122a9bae/"
                    }
                ],
                "FileScan-IO": {
                    "verdict": "LIKELY_MALICIOUS",
                    "threatlevel": "0.75",
                    "confidence": "1.0",
                    "report_link": "https://www.filescan.io/uploads/6a107acf875badc3b39272be/reports/8d289ee8-3656-40e8-ac17-436e359b26dd/overview"
                },
                "Kaspersky": {
                    "verdict": "Malware",
                    "file_type": "dll x64",
                    "first_seen": "2026-05-22T13:20:00Z",
                    "last_seen": "2026-05-22T23:55:00Z",
                    "hitscount": 10,
                    "report_link": "https://opentip.kaspersky.com/710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8/results?tab=lookup",
                    "detections": []
                }
            },
            "comments": null
        }
    ]
}
            

Related Reports

« Back
⚠ These IoCs were automatically extracted using regular expressions or an LLM and may include non-malicious data.