MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2402b0b9ac53cb4efc4b51e974a8c533fd1254fb2f65636ff7d3bbbde63d294a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2402b0b9ac53cb4efc4b51e974a8c533fd1254fb2f65636ff7d3bbbde63d294a
SHA3-384 hash: e5ff8ab8f2604e0448467b34b50fbef7c151c73e507298cb3bd51c5386b5a3786875132949a528e9ee98df6551d37c5e
SHA1 hash: 7c445774fff29e7df40814b46f0550d16984ce9d
MD5 hash: f68fe9d0602920deed45aa8eae0cc2f7
humanhash: golf-charlie-apart-nevada
File name:OC CVE6535 _TVOP-MIO 20C 2020.r00
Download: download sample
Signature RemcosRAT
File size:162'682 bytes
First seen:2020-10-21 10:04:38 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 3072:iqgXGBhe0MciwybbUpD3/1keytPMUpnsFoy2Ml3FZEUlXZ:iqgXGccdybb6/ueytkUsomvZEw
TLSH F0F31234B09E9D31A59EE5938437C4762ADCACD304E88C69BEAFCCB9D94410738D6753
Reporter abuse_ch
Tags:r00 RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: cloudserver10.qpc.co.th
Sending IP: 203.154.39.142
From: Nelly Juarez Reyes <njuarez@plasticoskasse.com.ar>
Subject: RE: CONFIRMACIÓN DE PEDIDO CVE6535
Attachment: OC CVE6535 _TVOP-MIO 20C 2020.r00 (contains "OC CVE6535 _TVOP-MIO 20(C) 2020,pdf.exe")

RemcosRAT C2:
insidelife1.ddns.net:8811 (216.38.7.231)

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2020-10-20 21:36:57 UTC
AV detection:
11 of 48 (22.92%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

r00 2402b0b9ac53cb4efc4b51e974a8c533fd1254fb2f65636ff7d3bbbde63d294a

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments