s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb high

📛 Threat Title

RemusStealer: QuickFetch.exe

Category: RemusStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 4442480 bytes. Tags: dropped-by-OffLoader, exe, RemusStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 17:52:41.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash d42595b695fc008ef2c56aabd8efd68e

IOC database

Type
hash_imphash
Value
d42595b695fc008ef2c56aabd8efd68e
First seen
Last seen
Attached to this threat
Appears in
423 threats
Description
imphash of URLhaus payload a7b9f3dda435b7f2…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb

IOC database

Type
hash_sha256
Value
34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
RemusStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 c0e5cd838da91492250cf5c1752020db95340ea9

IOC database

Type
hash_sha1
Value
c0e5cd838da91492250cf5c1752020db95340ea9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 83749ec9ab71f68a4b8b816755add83a

IOC database

Type
hash_md5
Value
83749ec9ab71f68a4b8b816755add83a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 4442480 bytes. Tags: dropped-by-OffLoader, exe, RemusStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 17:52:41.

Remediations (10)

  • web:any.run

    Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

  • web:bazaar.abuse.ch

    RemusStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as RemusStealer . Database Entry

  • web:bazaar.abuse.ch

    Information on RemusStealer malware sample (SHA256 ffa78f3d4b1dafb9723e6a68456e42a57c0a109b9b8246196e1a8a6d6d2d6f5a) MalwareBazaar uses YARA rules from several public ...

  • web:github.com

    - Users attempting to download C++ IDE from an open-source site are redirected to fake MEGA Transfer pages delivering RemusStealer . - The redirection utilizes an on-click mechanism driven through externally loaded CloudFront-hosted JavaScript infrastructure, which contains browser fingerprinting ...

  • web:medium.com

    Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct…

  • web:radar.offseq.com

    Detailed information about Remus Stealer - 64bit evolution of Lumma. Get real-time updates, technical details, and mitigation strategies.

  • web:www.joesandbox.com

    Signatures Found malware configuration Multi AV Scanner detection for submitted file Yara detected REMUS Stealer Found direct / indirect Syscall (likely to bypass EDR) Injects a PE file into a foreign processes Modifies the context of a thread in another process (thread injection) AV process strings found (often used to terminate AV products) Contains functionality to call native functions ...

  • web:www.joesandbox.com

    AI Summary Source: Malware # Malware Analysis Summary ## Overview QuickFetch.exe is an information stealer malware identified as REMUS Stealer with GO Stealer components. The sample exhibits extensive credential and cryptocurrency theft capabilities, anti-analysis techniques, and command-and-control infrastructure.

  • web:www.pcrisk.com

    What kind of malware is Remus? Remus is a stealer associated with Lumma. It shares similar capabilities, including the ability to steal browser passwords, cookies, and cryptocurrency wallet information. It is considered to be an evolution of Lumma (not a separate malware). Remus uses new techniques such as EtherHiding and improved anti-analysis checks. More about Remus Remus likely evolved ...

  • web:www.securitricks.com

    RemusStealer on Securitricks: related threat intelligence, IOCs, and MITRE context.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.