MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 3fa61293298e2f0d9d41d7231ef6ebbc9a977bc845b26e57f29adf747c0bd27d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 4
| SHA256 hash: | 3fa61293298e2f0d9d41d7231ef6ebbc9a977bc845b26e57f29adf747c0bd27d |
|---|---|
| SHA3-384 hash: | f011226da9ac80a1d2f03ac11903679221823e8720401230418e7fd9eef7ebb21acfeda29fceb03c6683bb26757cee3b |
| SHA1 hash: | aace84aaa764687b34b2d80b338bcf20173bcb71 |
| MD5 hash: | 44af9ca498a8409cbc86e1a222d5ffe0 |
| humanhash: | nitrogen-nebraska-kentucky-bulldog |
| File name: | UPS Details.img |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'376'256 bytes |
| First seen: | 2020-10-23 11:33:30 UTC |
| Last seen: | 2020-10-23 11:33:50 UTC |
| File type: | img |
| MIME type: | application/x-iso9660-image |
| ssdeep | 12288:A6BVKjy2EkrJP6/QsGYtPTvM9C8Cif/l6I0GqvvcVZBU9rRDlnZzYU:AYVKjy2EkrJPh07EhvwP0qRZG |
| TLSH | 8F55CF0223E89F18F5BF57389524101057F9BD42AB27D2ADBDD140DE1EB2B818F56B2B |
| Reporter | |
| Tags: | img nVpn RAT RemcosRAT UPS |
abuse_ch
Malspam distributing RemcosRAT:HELO: grace3
Sending IP: 52.175.253.95
From: "UPS Customer Service" <pkinfo@ups.com>
Subject: UPS - Package Arrival Notification
Attachment: UPS Details.img (contains "6LLq1Biu3Aqcf0n.exe")
RemcosRAT C2s:
u875414.nsupdate.info
u875414.nvpn.to
u875414.ddns.net
u875414.duckdns.org
Intelligence
File Origin
# of uploads :
2
# of downloads :
85
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.Taskun
Status:
Malicious
First seen:
2020-10-23 10:30:15 UTC
File Type:
Binary (Archive)
Extracted files:
22
AV detection:
17 of 29 (58.62%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Remcos
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
RemcosRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.