MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 2ef4b0178245cd534a201a7bd4ffd9522d0d67a9af1d439c712027e8250397ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 4
| SHA256 hash: | 2ef4b0178245cd534a201a7bd4ffd9522d0d67a9af1d439c712027e8250397ee |
|---|---|
| SHA3-384 hash: | a202d1785c027ed934d2262f5be779673986e4d05c64d910c36b993938c11179ffdf798b29055d01c6234ae2bf3e69bf |
| SHA1 hash: | e032306143c5b657d32277994e377bec314c02a6 |
| MD5 hash: | 45ba81a584f70a8708ba16917d7eb8e0 |
| humanhash: | ceiling-papa-march-september |
| File name: | DHL_Shipment_Notofication554334.xz |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 331'233 bytes |
| First seen: | 2021-02-16 14:17:02 UTC |
| Last seen: | Never |
| File type: | xz |
| MIME type: | application/x-rar |
| ssdeep | 6144:thandthZ7RfO5B+RUigMZKQmicEXY33XWDJEDfYP/pBRvL2q+exeH1U:thaPzRGBAAMgQRfI3n6ECpmq3eH1U |
| TLSH | BE642346A4F026A3E9F42AE4DF4FDB069314748B77D8329A26BF83710CB56749D44B09 |
| Reporter | |
| Tags: | DHL RAT RemcosRAT xz |
abuse_ch
Malspam distributing RemcosRAT:From: "DHL | Global | Forwarding" <admin@kandaovr.com>
Subject: DHL Shipment Notifcation Service #65435677
Attachment: DHL_Shipment_Notofication554334.xz (contains "DHL_Shipment_Notofication#554334.exe")
RemcosRAT C2:
gustavobillz.duckdns.org:57439
Intelligence
File Origin
# of uploads :
1
# of downloads :
247
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2021-02-16 14:17:07 UTC
AV detection:
14 of 47 (29.79%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
RemcosRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.