MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2608f28c483eb15a94f9b5938d1bb156eb1a39ab0f4c1ef3e5167626fc15d7bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 2608f28c483eb15a94f9b5938d1bb156eb1a39ab0f4c1ef3e5167626fc15d7bd
SHA3-384 hash: aab8c989f61d9c88c70e0c2dd7e17f32c8168fcb5dc7b6801f062cf3279aaf45e8e47ae310771243ce19f96d98849f8f
SHA1 hash: 82c7b951c94909e814e0606f7f12bdb192241ad6
MD5 hash: 0b6caec8d5f6d7a63e600b8321e465c8
humanhash: sodium-edward-sodium-cardinal
File name:C.B.M PURCHASE ORDER_102220,pdf.iso
Download: download sample
Signature RemcosRAT
File size:1'167'360 bytes
First seen:2020-10-22 08:12:35 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:QfbnamhHbXW763V8d8OAqUo3priVlP3lVJN2wNkmRPxkcIhlwweV+8YZqckawUNO:Qf75m8OWo0l/iOk4PHIh+luYyej
TLSH 39456C127290C332C1369AB9CD5FA7BC59A5BE40AD247887FAFC3D4D6B35E80242B157
Reporter abuse_ch
Tags:iso RemcosRAT


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: s7.itlinkonline.com
Sending IP: 95.217.94.194
From: C.B.M. S.r.l. <sales1@cbm-srl.com>
Subject: C.B.M. PO_102120
Attachment: C.B.M PURCHASE ORDER_102220,pdf.iso (contains "C.B.M PURCHASE ORDER_102220,pdf.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-22 06:56:49 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

iso 2608f28c483eb15a94f9b5938d1bb156eb1a39ab0f4c1ef3e5167626fc15d7bd

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments