MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab7f954e190ee1cab1cba2a28fab7c3dd197ed5ed3d060194b0053028dcb85ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: ab7f954e190ee1cab1cba2a28fab7c3dd197ed5ed3d060194b0053028dcb85ee
SHA3-384 hash: 6865dca482bc6c629d07a31e853c723d0806547b65f2ab74751cb7ad481f9e2c5b736172a9afd1624b168099fedbbb08
SHA1 hash: cf03e7f2a8af2f88d4be9d537e47227bc48308c4
MD5 hash: 07a26b9d4d9fbea155a139f664d35760
humanhash: diet-carbon-mobile-earth
File name:fkfiif.r25
Download: download sample
Signature RemcosRAT
File size:241'933 bytes
First seen:2020-06-10 11:39:21 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:ByAcxlhV5YqAb+MrjA2CQ1cn7Gxw0x7s9dgPhG2:mxlX5YqAbbrjA2CQCn7GxHxQrChH
TLSH F7342388C39963D57E9C5DF0822977D01630192B4D9BB09F90FD66EE82C17DB921A8F0
Reporter abuse_ch
Tags:nVpn r25 RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: smtp2.hiworks.co.kr
Sending IP: 121.254.168.210
From: Barmon Ashik <bashik_sm@wontradingbd.com>
Reply-To: "Barmon Ashik" <bashik_sm@wontradingbd.com>
Subject: RE: CANADA ORDER
Attachment: fkfiif.r25 (contains "fkfiif.com")

RemcosRAT C2:
91.193.75.178:8769

Hosted on nVpn:

% Information related to '91.193.75.0 - 91.193.75.255'

% Abuse contact for '91.193.75.0 - 91.193.75.255' is 'abuse@kgb-vpn.org'

inetnum: 91.193.75.0 - 91.193.75.255
netname: NON-LOGGING-VPN-SERVICE
descr: Please note that we don't store any user data.
descr: Our main effort is not to make money, but to preserve values like the
descr: freedom of expression, the freedom of press, the right to data protection
descr: and informational self-determination.
descr: We ask all employees of Spamhaus and all self-proclaimed deputy sheriffs
descr: to stop your attacks against us.
country: EU
admin-c: KA7109-RIPE
tech-c: KA7109-RIPE
org: ORG-KHd1-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-END-MNT
mnt-by: KGB-MNT
mnt-routes: KGB-MNT
sponsoring-org: ORG-MW1-RIPE
created: 2012-06-04T11:05:55Z
last-modified: 2019-12-05T05:39:00Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-06-10 11:41:04 UTC
AV detection:
3 of 48 (6.25%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip ab7f954e190ee1cab1cba2a28fab7c3dd197ed5ed3d060194b0053028dcb85ee

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments