MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2ef4b0178245cd534a201a7bd4ffd9522d0d67a9af1d439c712027e8250397ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 2ef4b0178245cd534a201a7bd4ffd9522d0d67a9af1d439c712027e8250397ee
SHA3-384 hash: a202d1785c027ed934d2262f5be779673986e4d05c64d910c36b993938c11179ffdf798b29055d01c6234ae2bf3e69bf
SHA1 hash: e032306143c5b657d32277994e377bec314c02a6
MD5 hash: 45ba81a584f70a8708ba16917d7eb8e0
humanhash: ceiling-papa-march-september
File name:DHL_Shipment_Notofication554334.xz
Download: download sample
Signature RemcosRAT
File size:331'233 bytes
First seen:2021-02-16 14:17:02 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 6144:thandthZ7RfO5B+RUigMZKQmicEXY33XWDJEDfYP/pBRvL2q+exeH1U:thaPzRGBAAMgQRfI3n6ECpmq3eH1U
TLSH BE642346A4F026A3E9F42AE4DF4FDB069314748B77D8329A26BF83710CB56749D44B09
Reporter abuse_ch
Tags:DHL RAT RemcosRAT xz


Avatar
abuse_ch
Malspam distributing RemcosRAT:

From: "DHL | Global | Forwarding" <admin@kandaovr.com>
Subject: DHL Shipment Notifcation Service #65435677
Attachment: DHL_Shipment_Notofication554334.xz (contains "DHL_Shipment_Notofication#554334.exe")

RemcosRAT C2:
gustavobillz.duckdns.org:57439

Intelligence


File Origin
# of uploads :
1
# of downloads :
247
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2021-02-16 14:17:07 UTC
AV detection:
14 of 47 (29.79%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

xz 2ef4b0178245cd534a201a7bd4ffd9522d0d67a9af1d439c712027e8250397ee

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments