MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0c3853a3177ae7b8dc5a93d09c005bd5368dab374e68fce26151eaf52cc819d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0c3853a3177ae7b8dc5a93d09c005bd5368dab374e68fce26151eaf52cc819d8
SHA3-384 hash: 072fbc67a087491a652af8ffc44e9608a7c2ae0f986851aac77c421a4a7b4c834cfaa727a230f8b331912e6752b82c49
SHA1 hash: f1b25113d79cc71769e1b3680d0861e80ea15209
MD5 hash: e67c6047c15acc8e236f0d317e1827f2
humanhash: winner-sweet-carbon-artist
File name:SecuriteInfo.com.Trojan.Malware.103970502.6668.6594
Download: download sample
Signature RemcosRAT
File size:2'571'264 bytes
First seen:2021-09-28 11:17:59 UTC
Last seen:2021-09-28 12:09:04 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 16c8c7a62c852018ed02e453e144c998 (6 x DarkGate, 2 x LummaStealer, 1 x RemcosRAT)
ssdeep 49152:dR/KpmZubPf2S8W2ILeWl+C1p9jWy5Snd0eigXN:j/jtYLP1Sy5E0
Threatray 185 similar samples on MalwareBazaar
TLSH T106C55A16B288713ED4FB0B37893386505937BA61BA73CD5B5BF02A0C8F355902E3E656
File icon (PE):PE icon
dhash icon b298acbab2ca7a72 (2'327 x GCleaner, 1'631 x Socks5Systemz, 67 x RedLineStealer)
Reporter SecuriteInfoCom
Tags:exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
117
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
PolarisBiosEditor 1.7.2.zip
Verdict:
Malicious activity
Analysis date:
2020-11-25 19:34:18 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Clean
Maliciousness:
Result
Threat name:
Unknown
Detection:
unknown
Classification:
n/a
Score:
6 / 100
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
0c3853a3177ae7b8dc5a93d09c005bd5368dab374e68fce26151eaf52cc819d8
MD5 hash:
e67c6047c15acc8e236f0d317e1827f2
SHA1 hash:
f1b25113d79cc71769e1b3680d0861e80ea15209
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments