MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 025b2aa47a06822130415107a15a86827c0e578f495a5ce38219dc276bab1286. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 025b2aa47a06822130415107a15a86827c0e578f495a5ce38219dc276bab1286
SHA3-384 hash: 125d402b68654228d2196313e3fd93f6aa5ba131f232391fe198b27cee1852ad6bfd87068b039721354537369d7e1e32
SHA1 hash: 9ce2e9c0b19113951f464bcfbf2b0364942f7538
MD5 hash: cc447ee533c13cd4f66cd7185ff0332e
humanhash: arizona-table-apart-don
File name:Proof of Payment.7z
Download: download sample
Signature RemcosRAT
File size:314'260 bytes
First seen:2020-08-06 06:42:28 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:9Q33mXtTvY6TDDqdttJRjLfXWAQYweHjv7PDxryFoZSrf7xW0EzZYFbKTY+3:2338TA2W5JRj7WeXH/lyFoE7EnzZOKTd
TLSH D46423C8183DA25497851DD2CBC9692847FEFC2BCA85C9F781227E87C775CD60BA980D
Reporter abuse_ch
Tags:7z RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: [139.64.246.192]
Sending IP: 139.64.246.192
From: HBZ Bank Operations and Support Services <chris@powerengineering.co.za>
Subject: Proof of Payment
Attachment: Proof of Payment.7z (contains "Proof of Payment.exe")

RemcosRAT C2:
139.64.246.192:444

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-08-06 06:44:12 UTC
AV detection:
10 of 48 (20.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip 025b2aa47a06822130415107a15a86827c0e578f495a5ce38219dc276bab1286

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments