MB-34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb
high
📛 Threat Title
RemusStealer: QuickFetch.exe
Description
File type: exe. Size: 4442480 bytes. Tags: dropped-by-OffLoader, exe, RemusStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 17:52:41.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
d42595b695fc008ef2c56aabd8efd68e
IOC database
- Type
- hash_imphash
- Value
d42595b695fc008ef2c56aabd8efd68e- First seen
- Last seen
- Attached to this threat
- Appears in
- 423 threats
- Description
- imphash of URLhaus payload a7b9f3dda435b7f2…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb
IOC database
- Type
- hash_sha256
- Value
34ba0747cd912e37af2273f6b2bbfb579a9b806713f344925a39f6da2c0847bb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- RemusStealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
c0e5cd838da91492250cf5c1752020db95340ea9
IOC database
- Type
- hash_sha1
- Value
c0e5cd838da91492250cf5c1752020db95340ea9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
83749ec9ab71f68a4b8b816755add83a
IOC database
- Type
- hash_md5
- Value
83749ec9ab71f68a4b8b816755add83a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 4442480 bytes. Tags: dropped-by-OffLoader, exe, RemusStealer, signed. Reporter: iamaachum. First seen: 2026-08-04 17:52:41.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:bazaar.abuse.ch
RemusStealer malware samples MalwareBazaar Database MalwareBazaar tries to identify the malware family (signature) of submitted malware samples. A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as RemusStealer . Database Entry
-
web:bazaar.abuse.ch
Information on RemusStealer malware sample (SHA256 ffa78f3d4b1dafb9723e6a68456e42a57c0a109b9b8246196e1a8a6d6d2d6f5a) MalwareBazaar uses YARA rules from several public ...
-
web:github.com
- Users attempting to download C++ IDE from an open-source site are redirected to fake MEGA Transfer pages delivering RemusStealer . - The redirection utilizes an on-click mechanism driven through externally loaded CloudFront-hosted JavaScript infrastructure, which contains browser fingerprinting ...
-
web:medium.com
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct…
-
web:radar.offseq.com
Detailed information about Remus Stealer - 64bit evolution of Lumma. Get real-time updates, technical details, and mitigation strategies.
-
web:www.joesandbox.com
Signatures Found malware configuration Multi AV Scanner detection for submitted file Yara detected REMUS Stealer Found direct / indirect Syscall (likely to bypass EDR) Injects a PE file into a foreign processes Modifies the context of a thread in another process (thread injection) AV process strings found (often used to terminate AV products) Contains functionality to call native functions ...
-
web:www.joesandbox.com
AI Summary Source: Malware # Malware Analysis Summary ## Overview QuickFetch.exe is an information stealer malware identified as REMUS Stealer with GO Stealer components. The sample exhibits extensive credential and cryptocurrency theft capabilities, anti-analysis techniques, and command-and-control infrastructure.
-
web:www.pcrisk.com
What kind of malware is Remus? Remus is a stealer associated with Lumma. It shares similar capabilities, including the ability to steal browser passwords, cookies, and cryptocurrency wallet information. It is considered to be an evolution of Lumma (not a separate malware). Remus uses new techniques such as EtherHiding and improved anti-analysis checks. More about Remus Remus likely evolved ...
-
web:www.securitricks.com
RemusStealer on Securitricks: related threat intelligence, IOCs, and MITRE context.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.