MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 0dc9425a8ee2cccd1548137ca474b28287d9d07c483e287405ddedea7791619e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 4
| SHA256 hash: | 0dc9425a8ee2cccd1548137ca474b28287d9d07c483e287405ddedea7791619e |
|---|---|
| SHA3-384 hash: | 62fe36a44fd3aa2f2aec0708fa41743f1eca1d1f84c09dfe86633afc0bfc95b1490701704beeae355b9129f82281af50 |
| SHA1 hash: | cc3c0d50af93092eab2b487613b367f44e114eba |
| MD5 hash: | 0ecf0748977aa11d64bbe09134f37166 |
| humanhash: | pluto-spring-table-single |
| File name: | Dell ordine-09362-9-11-2020.rar |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 470'638 bytes |
| First seen: | 2020-11-09 15:43:13 UTC |
| Last seen: | Never |
| File type: | rar |
| MIME type: | application/x-rar |
| ssdeep | 6144:gUX2DUaAIy5EodUhpU2ve6r6kAFnP7m1tNs+0ufg/eJk/7uKBz6x5ketAKUHCvoC:gUGU5EYU9vepjNPQQMfEX7jH/uvoSuRe |
| TLSH | 31A423AE89123826AC7ED5EC44E74D881C4E763AF27C0D01712DBF96D3A3B0D19A5E4D |
| Reporter | |
| Tags: | rar |
abuse_ch
Malspam distributing unidentified malware:HELO: mail.annexa3.digital
Sending IP: 78.142.35.149
From: Ama L. Neel <sales@mail.annexa3.digital>
Subject: Dell Ordine-09362-9-11-2020
Attachment: Dell ordine-09362-9-11-2020.rar (contains "Dell ordine-09362-9-11-2020.scr")
Intelligence
File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NetWiredRc
Status:
Malicious
First seen:
2020-11-09 07:43:48 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.