MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f33f4da872b93eb800770dbe291f58ff7ffdbe5b215056a7e0a9983e1705815. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3f33f4da872b93eb800770dbe291f58ff7ffdbe5b215056a7e0a9983e1705815
SHA3-384 hash: bb6c71b4bd68bc17b0935255d7abd0f215fd2ea18e7cd78a065716dbd8f7ec626f5d47fc01cdb3b7ef6cc582903298e2
SHA1 hash: 6e192bdad7807af75b564cfb1c8e44f287021fa9
MD5 hash: 0459b4592f5212136c11fa366fc07330
humanhash: winner-charlie-zebra-potato
File name:HBL10909LIT266NR5272RBL2021PRD66178278_LAX2778.PDF.cab
Download: download sample
Signature RemcosRAT
File size:274'720 bytes
First seen:2021-03-10 12:23:48 UTC
Last seen:Never
File type: cab
MIME type:application/vnd.ms-cab-compressed
ssdeep 6144:3TH8ywf62JgddvVPBcmIhpM8SywPK42XYARFKFvkB4SRyDPu:3rFWgdd9B+M8eKFxf88EDPu
TLSH 6D442312F6DACDACE9C391E0AB17C7DC1E72B4181EC5440A496FA938755DE9E2C8DC23
Reporter abuse_ch
Tags:cab HostGator


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gateway36.websitewelcome.com
Sending IP: 192.185.199.121
From: Lucy Yhang <operations@ultimateprofitbooster.com>
Subject: ENQUIRY: SHIPMENT FROM GEK ELETRONICS //FCL // HBL10909LIT266NR5272RBL2021PRD66178278_LAX2778
Attachment: HBL10909LIT266NR5272RBL2021PRD66178278_LAX2778.PDF.cab (contains "HBL10909LIT266NR5272RBL2021PRD66178278_LAX2778.PDF.scr")

Intelligence


File Origin
# of uploads :
1
# of downloads :
121
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Gathering data
Threat name:
Win32.Adware.DealPly
Status:
Malicious
First seen:
2021-03-10 12:24:16 UTC
AV detection:
18 of 45 (40.00%)
Threat level:
  1/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

cab 3f33f4da872b93eb800770dbe291f58ff7ffdbe5b215056a7e0a9983e1705815

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments