🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 02499e35a4c7f0cd87c60a05ea4013fedf5c6832841fa7467b6dc1f8828e8625. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 02499e35a4c7f0cd87c60a05ea4013fedf5c6832841fa7467b6dc1f8828e8625
SHA3-384 hash: 9907ba8aca1d252a169aad3a07e53d81fc6b82beab5e7d8dd1f22ef2379802108a01b0ccc84b12bbde5392582b258b7b
SHA1 hash: a94116b3a49b8c57f61a6ff517b3dec7ad500d92
MD5 hash: 49401a6a6bb3cd112218666fcb04f897
humanhash: sad-arkansas-oklahoma-magnesium
File name:OFICIO Y DETALLE DE ACTUACIÓN JUDICIAL RAD.563213.tar
Download: download sample
Signature RemcosRAT
File size:1'617'139 bytes
First seen:2023-11-10 07:51:06 UTC
Last seen:Never
File type: tar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 8921
ssdeep 24576:kD/d4BFoQuzAUMybYVYQFADUEXzHmV/c5VjVhiFYoDEA2/q2dK/C79z0McnC6pmc:kp4PwzA3/YQFADUEXTBbWEkm7t4pV
TLSH T1067533FA7E0E3C141FE5B731D8528B1E0168A4E1EB97C256586C9C89DA1BFBC44E06D3
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter JAMESWT_WT
Tags:file-pumped pw-8921 remcos RemcosRAT tar

Intelligence


File Origin
# of uploads :
1
# of downloads :
116
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:OFICIO Y DETALLE DE ACTUACIÓN JUDICIAL RAD.563213.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:1'153'433'600 bytes
SHA256 hash: ee6cd7afc88234c9593f723e900ad46ebdb6f5d013edfb7705001cee6c71b634
MD5 hash: 5348f8320c30569823257c491d6492a5
De-pumped file size:667'648 bytes (Vs. original size of 1'153'433'600 bytes)
De-pumped SHA256 hash: e3dc39916e141fb0df650acc290cdb1f611f021c57608c1e3838a7c4251ad647
De-pumped MD5 hash: 542d7b3f4b6fbce28912835a40d5a833
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:pull rat
Behaviour
Creates scheduled task(s)
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Program crash
Suspicious use of SetThreadContext
Remcos
Malware Config
C2 Extraction:
fdvijkrfdsojnlmrfsdojnlmfrdvcj.con-ip.com:1997
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

tar 02499e35a4c7f0cd87c60a05ea4013fedf5c6832841fa7467b6dc1f8828e8625

(this sample)

  
Delivery method
Distributed via web download

Comments