MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1d85d02945f658026fd31530b8474df7c7f4db901dd7dede496d3c618e9b4a03. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 1d85d02945f658026fd31530b8474df7c7f4db901dd7dede496d3c618e9b4a03
SHA3-384 hash: 2a0da26cf06084ac488e5d239dd3c00d5cc08cf8b06dcedd6d5cc51de8b1db0a40b57146e9f56fb252e786db08dd1e7e
SHA1 hash: 4271a0c1f1b9b128fd19cb9fea214ec3a4d49321
MD5 hash: 3528585b959a65fe7f422f14ff86a7d2
humanhash: mexico-tennis-potato-charlie
File name:Nuevo pedido de confirmación ,pdf.rar
Download: download sample
Signature RemcosRAT
File size:167'736 bytes
First seen:2020-10-23 17:38:12 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 3072:p8auG6SpkN2WbzMOnSLGKVOiH2oDZHGQCiW9AR1gQYEkbHWUUp0J:p8auCpkgWMDqKzWo1mQCiK6KHb2UUE
TLSH 8DF31284396BD63B458A0F7FBEB1993D9B204650734D49B4CF8C1F74917E628853AE0E
Reporter abuse_ch
Tags:ESP geo rar RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: mail.nipponcarsrl.com.ar
Sending IP: 200.114.86.103
From: Ivan Bohman C.A. <info4@bohman.com.ec>
Subject: Nueva confirmación de pedido PO-1912679
Attachment: Nuevo pedido de confirmación ,pdf.rar (contains "Nuevo pedido de confirmación ,pdf.exe")

RemcosRAT C2:
zubbymoney4life.ddns.net

Intelligence


File Origin
# of uploads :
1
# of downloads :
129
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AgentTesla
Status:
Malicious
First seen:
2020-10-23 16:19:09 UTC
AV detection:
18 of 29 (62.07%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

rar 1d85d02945f658026fd31530b8474df7c7f4db901dd7dede496d3c618e9b4a03

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments