MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b58c6a333d32e3bd9e2fca922160a2173229155b2d400abbf34bd87bc3a4649. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 16


Intelligence 16 IOCs YARA 17 File information Comments

SHA256 hash: 3b58c6a333d32e3bd9e2fca922160a2173229155b2d400abbf34bd87bc3a4649
SHA3-384 hash: e76f60d32b21c2a7b0b6e68cdc411bbc59b7c05c9752008e082b0d5a08707dd7a13e08322ab86e72ff78428c10a5ffe9
SHA1 hash: b13c03adb71d4a84e9d147b787f87124e8feeb55
MD5 hash: 93d3c0323eb947856c78ac1a6acc8ec4
humanhash: whiskey-kilo-hamper-east
File name:invoice cum packing list #4?fdp.Scr.exe
Download: download sample
Signature RemcosRAT
File size:1'335'296 bytes
First seen:2024-05-08 08:35:13 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'462 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 24576:M/d65y7lRCm3BbylFYG3KsWyqaXknbhwqfgVrn9rFk9xcc:M18ylXY7YG3QzFwqfgVr9rFkTX
Threatray 4'018 similar samples on MalwareBazaar
TLSH T1C955015293A5064DD1A183B617653C201226BD56BDDFD938AF70BB9B3931F8080B36BF
TrID 69.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.0% (.EXE) Win64 Executable (generic) (10523/12/4)
6.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.2% (.EXE) Win32 Executable (generic) (4504/4/1)
1.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
File icon (PE):PE icon
dhash icon 0b133b333333330f (3 x RemcosRAT, 1 x RedLineStealer, 1 x PureLogsStealer)
Reporter abuse_ch
Tags:exe RAT RemcosRAT


Avatar
abuse_ch
RemcosRAT C2:
103.186.117.26:1177

Intelligence


File Origin
# of uploads :
1
# of downloads :
421
Origin country :
NL NL
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
3b58c6a333d32e3bd9e2fca922160a2173229155b2d400abbf34bd87bc3a4649.exe
Verdict:
Malicious activity
Analysis date:
2024-05-08 09:18:08 UTC
Tags:
rat remcos keylogger evasion

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade packed
Malware family:
MSIL Injector
Verdict:
Malicious
Result
Threat name:
Remcos, PrivateLoader, PureLog Stealer
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Detected Remcos RAT
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Remcos
Sigma detected: Scheduled temp file as task from temp location
Sigma detected: Suspicious File Creation In Uncommon AppData Folder
Snort IDS alert for network traffic
Uses dynamic DNS services
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected AntiVM3
Yara detected PrivateLoader
Yara detected PureLog Stealer
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1438104 Sample: invoice cum packing list #4... Startdate: 08/05/2024 Architecture: WINDOWS Score: 100 63 petrss.duckdns.org 2->63 65 geoplugin.net 2->65 87 Snort IDS alert for network traffic 2->87 89 Found malware configuration 2->89 91 Malicious sample detected (through community Yara rule) 2->91 95 17 other signatures 2->95 9 invoice cum packing list #4_fdp.Scr.exe 3 8 2->9         started        12 XxiiwkWsZyuZyh.exe 2->12         started        signatures3 93 Uses dynamic DNS services 63->93 process4 file5 55 C:\Users\user\AppData\LocalQFmReRfUw_.exe, PE32 9->55 dropped 15 LocalQFmReRfUw_.exe 6 9->15         started        19 Acrobat.exe 73 9->19         started        97 Antivirus detection for dropped file 12->97 99 Multi AV Scanner detection for dropped file 12->99 101 Contains functionality to bypass UAC (CMSTPLUA) 12->101 103 7 other signatures 12->103 21 XxiiwkWsZyuZyh.exe 12->21         started        23 schtasks.exe 12->23         started        25 XxiiwkWsZyuZyh.exe 12->25         started        signatures6 process7 file8 59 C:\Users\user\AppData\...\XxiiwkWsZyuZyh.exe, PE32 15->59 dropped 61 C:\Users\user\AppData\Local\...\tmpD43E.tmp, XML 15->61 dropped 77 Antivirus detection for dropped file 15->77 79 Multi AV Scanner detection for dropped file 15->79 81 Machine Learning detection for dropped file 15->81 85 3 other signatures 15->85 27 LocalQFmReRfUw_.exe 15->27         started        32 powershell.exe 15->32         started        34 powershell.exe 15->34         started        36 schtasks.exe 15->36         started        38 AcroCEF.exe 105 19->38         started        83 Detected Remcos RAT 21->83 40 conhost.exe 23->40         started        signatures9 process10 dnsIp11 73 petrss.duckdns.org 103.186.117.26, 1177, 49714 AARNET-AS-APAustralianAcademicandResearchNetworkAARNe unknown 27->73 75 geoplugin.net 178.237.33.50, 49721, 80 ATOM86-ASATOM86NL Netherlands 27->75 57 C:\ProgramData\remcos\logs.dat, data 27->57 dropped 105 Detected Remcos RAT 27->105 107 Installs a global keyboard hook 27->107 42 conhost.exe 27->42         started        109 Loading BitLocker PowerShell Module 32->109 44 conhost.exe 32->44         started        46 WmiPrvSE.exe 32->46         started        48 conhost.exe 34->48         started        50 conhost.exe 36->50         started        52 AcroCEF.exe 2 38->52         started        file12 signatures13 process14 dnsIp15 67 23.216.80.138, 443, 49725 CMCSUS United States 52->67 69 54.227.187.23, 443, 49723, 49724 AMAZON-AESUS United States 52->69 71 96.7.156.186, 443, 49722 AKAMAI-ASUS United States 52->71
Threat name:
ByteCode-MSIL.Backdoor.Bladabhindi
Status:
Malicious
First seen:
2024-05-08 08:36:05 UTC
File Type:
PE (.Net Exe)
Extracted files:
43
AV detection:
23 of 24 (95.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost execution rat
Behaviour
Checks processor information in registry
Creates scheduled task(s)
Modifies Internet Explorer settings
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Command and Scripting Interpreter: PowerShell
Remcos
Malware Config
C2 Extraction:
petrss.duckdns.org:1177
Unpacked files
SH256 hash:
295be96347c3ee2a2ba7f10e88267274d7b0c5cd7dcf14108f76ac03c5130520
MD5 hash:
35292829892ad204f2eb60fe087d3d3c
SHA1 hash:
c1729353c32c4620a835dd417076a2413fc8f675
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
cbe4153add0b29b67e77346f502369fd6430c3903dd15f66109169653a77a320
d223cfe6d16b1305e8b67cadaa79ebf9321a16c299ef1ccb71289b4ec4f30589
26d326d58b211204d13d7c4de057ecbc4d0d393862d33d200ac20d47c3329f79
1f9bb30664b00d710ecedcdd485de690c25e38199c86fc2fe350c7e11c660fd4
d36c75eeda6238e518fffee0f4b12fc0fc2e1d56d478e07b64e71814b0f4e1bb
3b58c6a333d32e3bd9e2fca922160a2173229155b2d400abbf34bd87bc3a4649
948c35522178c3c40726d13d55ad649ccfb2c242cb8cfc4524786e2bd4b13ba5
a745b4a8dbdad5c84183ce33793aac75423bdb99fd3a3fca646fbeb66e1059f2
74bc25305325ee41319153323e722fb21fa052f0e5b0006d12894e906efcd838
ca46f828ef9afce366976d3e6d5e06b8a7e1dcd971eda8ceca5c75289e81b688
7aca6825bcc57d37bd12f4975818ef6fb846766a335c1fd5f79b154d4ea89842
65b79e68d650ab1f2d6fc5d048b27bc44d54e5cb8f310932b3e18d034ecd234a
ee66629e98c3278017e7297d3b2b57aac9783a51a46b34046ccc866d10ba4f3c
7b3d904c7e1ef9ac37cf347bf40113e0f074b35004a90dc3bc2443312c4c1bfc
71eea3c3d6de8b4666d87e3771155bb9c372615eeb5519999ad2fda159f13968
ae16694e0640bfcb3d53389a2a11f459066625d9cfaf982a79b2bda3a26e97b6
93bf3f062ed4ad9f478559a984e2d13c646acabafc88c44e06e2a3e660ce3a58
9f0940b08d229480a45cd4f9d104ab5da0829dddcd968581aee5fad92b91fa80
4e0b653a92bc80b91eb6797f5b5d252710790117dd5fb0038ba15e36a58a4da3
b8f5159a474b7be7218d053df0795d326474f2d5f8deeff6c38d5141d3ecd4ee
27ac3f8a2082fcd8246bff0281e760d36edcaef16ef2831d14138b8df82ab86f
38c705a8dd3a80a55f20d881ce5e6c848201ba129ef8a8ba990cc3899d5b2a68
3cfce085b5cdc5db01a2223105789afda600249a89bad3a2e29066b4ab6050ae
561f3664b4dcc39b1eb79236231b0e36fb5fde10c8bda6d356d2fa63925f3a6b
1191d3f484d35c7e4d42ac7bcdd2227930f848383873d914e8010bfe637e0122
SH256 hash:
4909093c1045073940daf73778f88ce3e5d4dcbc0d69e3498ad4672c2e699013
MD5 hash:
28b43a10958caef0465f7b93be0a0d77
SHA1 hash:
9c85c1cb7f6face0a6c8d0a2d2314a99092d6554
SH256 hash:
374853160b4d7d1f1fdbd9a251f3762aca2beef42a84f8a4a50473d1bd31e5d8
MD5 hash:
8ca9d635dccecacd7a66e33ed11cbb43
SHA1 hash:
102aaf9835f88bcf6e90783619931a4437c99920
SH256 hash:
1a10bce1505770c8157788feaf15fc3af1337a46a0cf8c0265bb55506462e3a1
MD5 hash:
3a026e4f0c507b071e4471fb2e3bd15f
SHA1 hash:
0daece05be76ddd8f11359417314d231abc7507c
Detections:
Remcos win_remcos_w0 win_remcos_auto malware_windows_remcos_rat INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
SH256 hash:
84baf4732e701bf5e96d112eb70df2d713ec074ce870ede1ac01d8f2c0029e53
MD5 hash:
f18757b9bfd6fb7e53ded5b2e55a2e70
SHA1 hash:
ba5288a1233c8147a551c0de81fb8fc1a31a7ad5
SH256 hash:
3b58c6a333d32e3bd9e2fca922160a2173229155b2d400abbf34bd87bc3a4649
MD5 hash:
93d3c0323eb947856c78ac1a6acc8ec4
SHA1 hash:
b13c03adb71d4a84e9d147b787f87124e8feeb55
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:iexplorer_remcos
Author:iam-py-test
Description:Detect iexplorer being taken over by Remcos
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:NET
Author:malware-lu
Rule name:NETexecutableMicrosoft
Author:malware-lu
Rule name:pe_imphash
Rule name:Remcos
Author:kevoreilly
Description:Remcos Payload
Rule name:REMCOS_RAT_variants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Remcos_b296e965
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.
Rule name:win_remcos_w0
Author:Matthew @ Embee_Research
Description:Detects strings present in remcos rat Samples.
Rule name:yarahub_win_remcos_rat_unpacked_aug_2023
Author:Matthew @ Embee_Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments