MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0dc9425a8ee2cccd1548137ca474b28287d9d07c483e287405ddedea7791619e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0dc9425a8ee2cccd1548137ca474b28287d9d07c483e287405ddedea7791619e
SHA3-384 hash: 62fe36a44fd3aa2f2aec0708fa41743f1eca1d1f84c09dfe86633afc0bfc95b1490701704beeae355b9129f82281af50
SHA1 hash: cc3c0d50af93092eab2b487613b367f44e114eba
MD5 hash: 0ecf0748977aa11d64bbe09134f37166
humanhash: pluto-spring-table-single
File name:Dell ordine-09362-9-11-2020.rar
Download: download sample
Signature RemcosRAT
File size:470'638 bytes
First seen:2020-11-09 15:43:13 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:gUX2DUaAIy5EodUhpU2ve6r6kAFnP7m1tNs+0ufg/eJk/7uKBz6x5ketAKUHCvoC:gUGU5EYU9vepjNPQQMfEX7jH/uvoSuRe
TLSH 31A423AE89123826AC7ED5EC44E74D881C4E763AF27C0D01712DBF96D3A3B0D19A5E4D
Reporter abuse_ch
Tags:rar


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: mail.annexa3.digital
Sending IP: 78.142.35.149
From: Ama L. Neel <sales@mail.annexa3.digital>
Subject: Dell Ordine-09362-9-11-2020
Attachment: Dell ordine-09362-9-11-2020.rar (contains "Dell ordine-09362-9-11-2020.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Backdoor.NetWiredRc
Status:
Malicious
First seen:
2020-11-09 07:43:48 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

rar 0dc9425a8ee2cccd1548137ca474b28287d9d07c483e287405ddedea7791619e

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments