MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2608f28c483eb15a94f9b5938d1bb156eb1a39ab0f4c1ef3e5167626fc15d7bd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 3
| SHA256 hash: | 2608f28c483eb15a94f9b5938d1bb156eb1a39ab0f4c1ef3e5167626fc15d7bd |
|---|---|
| SHA3-384 hash: | aab8c989f61d9c88c70e0c2dd7e17f32c8168fcb5dc7b6801f062cf3279aaf45e8e47ae310771243ce19f96d98849f8f |
| SHA1 hash: | 82c7b951c94909e814e0606f7f12bdb192241ad6 |
| MD5 hash: | 0b6caec8d5f6d7a63e600b8321e465c8 |
| humanhash: | sodium-edward-sodium-cardinal |
| File name: | C.B.M PURCHASE ORDER_102220,pdf.iso |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'167'360 bytes |
| First seen: | 2020-10-22 08:12:35 UTC |
| Last seen: | Never |
| File type: | iso |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:QfbnamhHbXW763V8d8OAqUo3priVlP3lVJN2wNkmRPxkcIhlwweV+8YZqckawUNO:Qf75m8OWo0l/iOk4PHIh+luYyej |
| TLSH | 39456C127290C332C1369AB9CD5FA7BC59A5BE40AD247887FAFC3D4D6B35E80242B157 |
| Reporter | |
| Tags: | iso RemcosRAT |
abuse_ch
Malspam distributing unidentified malware:HELO: s7.itlinkonline.com
Sending IP: 95.217.94.194
From: C.B.M. S.r.l. <sales1@cbm-srl.com>
Subject: C.B.M. PO_102120
Attachment: C.B.M PURCHASE ORDER_102220,pdf.iso (contains "C.B.M PURCHASE ORDER_102220,pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2020-10-22 06:56:49 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
5/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.