MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fbac26d1db7fce1f1ddc5c552ab50ac44888d906e355f2a9187544a52cb8c94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 17


Intelligence 17 IOCs YARA 34 File information Comments

SHA256 hash: 1fbac26d1db7fce1f1ddc5c552ab50ac44888d906e355f2a9187544a52cb8c94
SHA3-384 hash: ffff442631f8ac0acb14430e2f6a56af5c67454720ce0e79bef2c81cba6385a90c2dacc1ff52107b9e32fe5fdf67c381
SHA1 hash: 33000bdfc8ddf75bf48f788645ecc6c028a23278
MD5 hash: 1edf4ab8bd9f71ada01b5cd4763c555d
humanhash: rugby-cold-zulu-michigan
File name:proof of paymentt.exe
Download: download sample
Signature RemcosRAT
File size:976'896 bytes
First seen:2024-05-03 09:19:40 UTC
Last seen:2024-05-03 10:25:01 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 24576:twmCJ4qDVpHWXj1qmmpTjabFQx4jKkihiLvEbWnhX0R1EPyOFXqva:U+qbWXhqmsIy4xihGvEbmRaOs
Threatray 3'987 similar samples on MalwareBazaar
TLSH T1EB25230BF56AFF64E92413B445A5888D53B8D4119231F7635EC624C33F53BA826DEB23
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
File icon (PE):PE icon
dhash icon 2649c96969c9c836 (12 x AgentTesla, 4 x Formbook, 1 x RemcosRAT)
Reporter abuse_ch
Tags:exe RAT RemcosRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
358
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
1fbac26d1db7fce1f1ddc5c552ab50ac44888d906e355f2a9187544a52cb8c94.exe
Verdict:
Malicious activity
Analysis date:
2024-05-03 09:32:39 UTC
Tags:
rat remcos remote evasion keylogger stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a process with a hidden window
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
Connection attempt
Sending a custom TCP request
DNS request
Sending an HTTP GET request
Searching for synchronization primitives
Reading critical registry keys
Launching the default Windows debugger (dwwin.exe)
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade obfuscated packed
Result
Threat name:
Remcos, PureLog Stealer
Detection:
malicious
Classification:
rans.phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
Adds a directory exclusion to Windows Defender
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Detected Remcos RAT
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Remcos
Sigma detected: Scheduled temp file as task from temp location
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected PureLog Stealer
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1435883 Sample: proof of paymentt.exe Startdate: 03/05/2024 Architecture: WINDOWS Score: 100 61 geoplugin.net 2->61 75 Found malware configuration 2->75 77 Malicious sample detected (through community Yara rule) 2->77 79 Antivirus detection for URL or domain 2->79 81 18 other signatures 2->81 8 proof of paymentt.exe 7 2->8         started        12 mQpdTSxCjbPop.exe 5 2->12         started        14 chrome.exe 9 2->14         started        signatures3 process4 dnsIp5 51 C:\Users\user\AppData\...\mQpdTSxCjbPop.exe, PE32 8->51 dropped 53 C:\Users\user\AppData\Local\...\tmp73D0.tmp, XML 8->53 dropped 93 Adds a directory exclusion to Windows Defender 8->93 95 Injects a PE file into a foreign processes 8->95 17 proof of paymentt.exe 3 16 8->17         started        22 powershell.exe 23 8->22         started        24 schtasks.exe 1 8->24         started        97 Multi AV Scanner detection for dropped file 12->97 99 Contains functionality to bypass UAC (CMSTPLUA) 12->99 101 Contains functionalty to change the wallpaper 12->101 103 5 other signatures 12->103 26 mQpdTSxCjbPop.exe 12->26         started        28 schtasks.exe 1 12->28         started        63 192.168.2.4 unknown unknown 14->63 65 192.168.2.5, 138, 2269, 443 unknown unknown 14->65 67 2 other IPs or domains 14->67 30 chrome.exe 14->30         started        file6 signatures7 process8 dnsIp9 55 37.120.235.122, 2269, 49707, 49709 SECURE-DATA-ASRO Romania 17->55 57 geoplugin.net 178.237.33.50, 49712, 80 ATOM86-ASATOM86NL Netherlands 17->57 49 C:\ProgramData\remcos\logs.dat, data 17->49 dropped 83 Detected Remcos RAT 17->83 85 Tries to harvest and steal browser information (history, passwords, etc) 17->85 87 Maps a DLL or memory area into another process 17->87 89 Installs a global keyboard hook 17->89 32 proof of paymentt.exe 17->32         started        35 proof of paymentt.exe 17->35         started        37 proof of paymentt.exe 16 17->37         started        47 2 other processes 17->47 91 Loading BitLocker PowerShell Module 22->91 39 WmiPrvSE.exe 22->39         started        41 conhost.exe 22->41         started        43 conhost.exe 24->43         started        45 conhost.exe 28->45         started        59 www.google.com 142.251.41.4, 443, 49716, 49717 GOOGLEUS United States 30->59 file10 signatures11 process12 signatures13 69 Tries to steal Instant Messenger accounts or passwords 32->69 71 Tries to steal Mail credentials (via file / registry access) 32->71 73 Tries to harvest and steal browser information (history, passwords, etc) 35->73
Threat name:
Win32.Infostealer.Limitail
Status:
Malicious
First seen:
2024-05-03 09:20:08 UTC
File Type:
PE (.Net Exe)
Extracted files:
1
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection execution rat spyware stealer
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Checks computer location settings
Reads user/profile data of web browsers
Command and Scripting Interpreter: PowerShell
NirSoft MailPassView
NirSoft WebBrowserPassView
Nirsoft
Remcos
Malware Config
C2 Extraction:
37.120.235.122:2269
Unpacked files
SH256 hash:
4a2731cefafcd2a31c9bcb524b7f61fc8bbe86dcd073aff0f326ee82a8738dfe
MD5 hash:
ddaf62043c46688a41085b2852ec4624
SHA1 hash:
bfe2982124091ae44b39195e37275ebfebd287e5
SH256 hash:
4909093c1045073940daf73778f88ce3e5d4dcbc0d69e3498ad4672c2e699013
MD5 hash:
28b43a10958caef0465f7b93be0a0d77
SHA1 hash:
9c85c1cb7f6face0a6c8d0a2d2314a99092d6554
SH256 hash:
ecfcf7bf21fd1622c27d30c6a57ed9c362d2acdb2812a6f803b53e22d422eb32
MD5 hash:
a5192e30cc1ec9efbdf7fc4f91fc1475
SHA1 hash:
84cd8dc05061fb59bca5d3985227c8eaa264bf24
Detections:
Remcos win_remcos_w0 win_remcos_auto malware_windows_remcos_rat INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
SH256 hash:
b8edfb5c6d479f3f26eb5ed1ba7ed78cd8d748bbf5ae4c8cb38ba5dc1548d887
MD5 hash:
16dd8e9cc8a722a5965102565ec26ad7
SHA1 hash:
7cba0efef3c8535ffe6e60d33cbdc83d87193824
SH256 hash:
730d20d7e5e757e99a45b93fadd70c8553a8ae7d7eb8ea10aacb2daf0675dbb9
MD5 hash:
308c4e14221c10ffd9b19b4adb2c39d0
SHA1 hash:
47333f54d93f99f7fea55ab84dce316a108ef21f
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
1c9d7294c27649d4749a4a3e8c08cdd88fab4e7835cda473a6dde5aca7080a48
2c6881e7cdd40a5dd6013fd96a8c75c67b912c43ea37140bd5cc06ee1cfb67d9
382c18e960b53aad4de8307b152163aa4e726c4ef35844784d86c5bcbeeea5d7
548e403cfad22d1e87842b66925f31b64cae77d1f5371b845cb1dcd66fe99a92
19e927ad852077f6b47f21cc42d5fad6499b748e8a68295306ecc0889b4c8092
0d0ad0b643823f666030579fc18c8f4bca63e0012db299ea5cb51d05da892b83
0eebf72cc9f4ef61a8f3156e1c01ba3925678f75522e494abcde74c3eadc9e85
c4fb07b68ad0d0b45a6571e19ae2ac2759b094b18ba9cb560595253ac2a54380
d8fd8387dccd0c2884b3a17ca71477d8dee15b5b445fd9a0ac37fe29ca91440a
9b2a20382a2f0aa6745217b19f51ba20f0e9bf07121ae3ff6aa0ec74850b0507
ca4db0fd02f9a6e22c53d273087156269b720cf0b92140c67cc0cbc9d279cc26
d0470bacce95da182a6ac0f381c45fdc9dffe39bb58d491c63ecd2c98de7689b
094f62c5791469b0fb9c210f61caaa8b4e6d5c1901672548435fd2897ac00bad
2363d23876a13f38f92ae169c04f2d12bb3ab6a027b4f46f144aef5a02ee0105
94e86d7455f9c08cc57d6706e0f779a59459fbdac1506d5b12f20566ad2b9cce
506fdcc4444cd91f71713b3335a02f6612f0ac3821b5b098fac837a676aa1c04
0db3ba2e07241d72af3202addf1d990e270a2d300fb91c8d13b1ecdf4db414e7
8996d33ea6bf05f6bda3a0a4f1ee4fceff1b49e99112d387ea5ac87ae778fcb6
5e8780c77ab8e6dd109c6a24102822db21effaa4a2e3d4b1fdad1fa1567c40fe
9ebcdbb67714c0618c1e9f3acb0cea1906a85ba19e5da275840ce6fec77b61c4
418f0f099c70fa88460becd3b8d10992f68dacf4dba44370abdde90292d508d6
df47764a3743f716aebeda76dcef39830373f2bee2e5f3f99f86d5fd74a0fd01
ca0bf7bb5880f8af7bfc35f0dba6fde5c68dd7212f02ed4f70260004e4effc98
5cefeec91fba3d10f09757957852615247443e53f670da3c2af2c3c8aae068d5
707bbd9a748b709cca51737b3a5221c2f77090fa4af2d2bde2598d8fb08e558e
9745e0d21f50b1c553b40e8c353b11bb172a2bae1a83b3b9cfce26f9e01b3b89
3c29b509fac248a90cdb5970352752041fe1c02034f06b81182c5bb8b311766f
ecbd820686317cc38e97ceac59f26f853bd924695b2d124c4e87f5f48c82bd63
56f69825010da76642ee25cf55098c51f6ded6f6fe2718b6c69c1c4b74b57c65
46bcdad83987e1387a004286f7d130d90ba48d850b695c93e9ac1c6c1575ec64
3d4bbaa7741c371e24b99a016e735dfe3f70004f9997eb8aec4908aa9d07e0d0
9d18f6e38273eb6a8959627210f55baf459975af7a75195e108613bfd3da858a
d6ac0eeecda07bab17a4dde0ed70aae89398fd8a85c5cfc419b3e548711f43d0
21e7743ee49b00d201af99fbd9fc0a430032f416070834294b12f3ea2c12b48d
684ffb1891b99bea409dd7dc5a43e6e5ab9f7b32dfd4340144bed9d459915ce7
c20656be388f493743b1724c04112b0b325174ffacb1e86c098f63701320c63e
2c18caf218754162e1a073943a4be6ea584f8e54b20d9287aa26fd6828d99efc
bd60848c5c86d483a65707d9c596938371a2967f18d6eb2f5c3db1140cce2ae2
f7b10eb48e40c12e9f6b2ddea4399165abfad2bfb67da017aa31180b762138be
1fbac26d1db7fce1f1ddc5c552ab50ac44888d906e355f2a9187544a52cb8c94
bf67c14947375eb710ccdb9884fd14c1c46a38b7d5a0e98908d017f0af7af4e5
1d2489091a940784cf67661f2f4db40febdfd98e0d9b38e5de4ac98485666d4e
e5435dd5c1dab1fd1a738ddf914ea9af64e89daa4b141b3075f53f0960805dbe
c040726eab61fc794f91f7d7712de11b4955c76db950e3b85ef57d413b15eb87
6703df15130444806d68473d071445cfe26efb0570f06df656711a74d18264f6
16bbd2adc990bd136c25b0a4d4336c2f91a814cb8a71dd767ec9c09ec5ae323f
9e39036b1848c9867521dca9c5e351a69b235b42f760e714f20ae3465ef9b559
5db6537a9455294a3b236e740b3d2ff1078f49a901949ba167a55fe62a09787c
0d5548b7d4696c67dba1d5bb827285ed2d3846fd0ad28140c198ad9c467f1bb0
69b09aa77f3774958809742c27dadfe0750ab0861a4b2e3d890cce77bb2370c2
7d0c488d900c633cfac5914cc35d1a31d3549710db2c9ce1612ae94ecf106dcc
4eedc7ed6ade620eef8eb160d18518afc9c59eb262baf8a9fdbe758fb611b6f0
c1c17e6ce5d7105fa6f75ceb4672492e23fe35ea438dc9a26481d893be427789
9a3d926c5cb6cc2df456a67267e3f99c29b1cdc90575a91e59d91ca3a1716b83
9e68a6dcf4297dda701425246945cac9200ef48bf6c0669e89d84bbb74c12dd6
5412e646089455c3aecbc199fd89d53e55ec54eee9302e0e523199df1a07f7ae
dc63606ac171f693a256efeabdbb8c47957edf0af01ac63d10f4f44a9a4e1f56
0144ad3c79e25335ba0bb88e4c47c497215af9d44f0dc9f8a550bf71d579ca07
37ac69abe12f3ec977df53efd9e10a1c2f40eba5fab217cbce4e0fb5452c669f
4ba45a9624e8fc73cf5a36e7be9966f01ada829dd88491202baff3b0bce9b6f5
c75750db51edf7db96de6dc7834621ed37d1c81a587ea076c16dcaeb190d6bf8
d6e7c231b0aeee159700e68b79eb19d932e851a64a4a82ad1a1c72efc2faa72b
1a220cf90de5204b1f33c388537f695421fc1388dd2ed8315efa211d0113ea6e
268c36f27645590a64c285888fa50d84b06183a27f4c92d598f269790286253a
ade549ccd5712bb079dcb72bbfb3955ee96e062055ab9e5768277a74d023db80
62ce98f7fcd773efa3deac85904b54c17b456af92b6e778c2adfc998bd07f5c3
2ee9df4aa846adb335d5bb9bbae3c279536be3032fc6282cf8501c1ce6ce8364
f505df30ae0f2bff06ff19080af9c11790a1e6b0896bdf3ca797c8ba9c036a98
0cfbe133465059e9d21adb0ee0bcf53ecb2f3459bc258b9a78c6a56cfbf15f27
f1eab19801011161336857ec73752f3c5f9f63654cb89149854205c4357635b5
09f202dbceb944c631fc597c7b929d3885d3a44faa9d0f8d332d13d593a9ca84
5daa414b78521010bf803ecd49376ea22488a7eff52bd8613d4ac17aa4addda0
9665879c5c26c6bce2c05c977f91dad5a19188059b4f380bec54a380f9f7c9c4
bed407ef928f705eb4662c4acdd0c422b059e8486165f3e0fb27c700b2da1a22
SH256 hash:
1fbac26d1db7fce1f1ddc5c552ab50ac44888d906e355f2a9187544a52cb8c94
MD5 hash:
1edf4ab8bd9f71ada01b5cd4763c555d
SHA1 hash:
33000bdfc8ddf75bf48f788645ecc6c028a23278
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:iexplorer_remcos
Author:iam-py-test
Description:Detect iexplorer being taken over by Remcos
Rule name:INDICATOR_EXE_Packed_MPress
Author:ditekSHen
Description:Detects executables built or packed with MPress PE compressor
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:QbotStuff
Author:anonymous
Rule name:Remcos
Author:kevoreilly
Description:Remcos Payload
Rule name:REMCOS_RAT_variants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:TeslaCryptPackedMalware
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Remcos_b296e965
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.
Rule name:win_remcos_w0
Author:Matthew @ Embee_Research
Description:Detects strings present in remcos rat Samples.
Rule name:yarahub_win_remcos_rat_unpacked_aug_2023
Author:Matthew @ Embee_Research
Rule name:yara_template

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments