MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c034ecfc5b98443264c65be7296caba84ddc9a39f11f3a7ad33c8f706f4aecc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2c034ecfc5b98443264c65be7296caba84ddc9a39f11f3a7ad33c8f706f4aecc
SHA3-384 hash: 776c4a146e168a041340d94a02c91c464f08bd1c8e568fe1d05efb026e4b1ea8b58f26535599b2f4e50ce08bdf7e9aa7
SHA1 hash: 4209674359af141a775475a4256175aa7d1389a9
MD5 hash: 625149e105911e048005cce375a17def
humanhash: beryllium-charlie-utah-delaware
File name:DHL_414568539649 receipt document,pdf.iso
Download: download sample
Signature RemcosRAT
File size:454'656 bytes
First seen:2020-06-10 07:24:43 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 6144:3JxkG1gF/hK1TpF0GyviWrU9/AG7HodYfHvU/X4sYGXW:c3hKVpF0ZvNUQYfHvU/oGXW
TLSH 49A4E5C0E2483CFDE81A17724D36AD252153BD7996B5502FA40FB42A9BF728334B2D5B
Reporter abuse_ch
Tags:DHL iso RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: cloudhost-67388.au-south-1.nxcli.net
Sending IP: 103.224.90.42
From: DHL Support <support@dhl.com>
Subject: Re: DHL Shipment Notification
Attachment: DHL_414568539649 receipt document,pdf.iso (contains "DHL_414568539649 receipt document,pdf.exe")

RemcosRAT C2:
nagod.ddns.net:8811 (216.38.7.231)

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Backdoor.NanoCore
Status:
Malicious
First seen:
2020-06-10 07:26:07 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

iso 2c034ecfc5b98443264c65be7296caba84ddc9a39f11f3a7ad33c8f706f4aecc

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments