MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 414641c411715dd041c11c11b0b935944b920be200bab08fe537edefc5c6d4b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 3
| SHA256 hash: | 414641c411715dd041c11c11b0b935944b920be200bab08fe537edefc5c6d4b7 |
|---|---|
| SHA3-384 hash: | 340d2a1f3db8c2b77936de8b7a26572629196d17512da745b41b29658067c24cdf035eeb409cb1e7a4e76c03f147282e |
| SHA1 hash: | 28cff4da385a84cfa71d452674b3fb47d5c480ff |
| MD5 hash: | dc7d0a2b5e14e1de962a26210383d578 |
| humanhash: | kansas-charlie-quebec-pizza |
| File name: | Payment_MT_103_776363_Swift_Confirmation.xz |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 32'294 bytes |
| First seen: | 2021-03-04 07:24:35 UTC |
| Last seen: | Never |
| File type: | xz |
| MIME type: | application/x-rar |
| ssdeep | 768:3VDOhJe9hHKsjHWBe4VTaf5Z2HAUggy8Vg:3Vane7HPjHK5YS7K |
| TLSH | 44E2E1356941D3402E8B37876A7B5E290C6C7D9CE378016008B765C7879DCFD6AABC1E |
| Reporter | |
| Tags: | RAT RemcosRAT xz |
abuse_ch
Malspam distributing RemcosRAT:HELO: mail.jetmails.xyz
Sending IP: 103.109.37.166
From: account <admin@jetmails.xyz>
Subject: Re: Payment Advice(MT103) TT/USD/2021
Attachment: Payment_MT_103_776363_Swift_Confirmation.xz (contains "Payment_MT_103_#776363_Swift_Confirmation.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
318
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
RemcosRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.