MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 414641c411715dd041c11c11b0b935944b920be200bab08fe537edefc5c6d4b7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 414641c411715dd041c11c11b0b935944b920be200bab08fe537edefc5c6d4b7
SHA3-384 hash: 340d2a1f3db8c2b77936de8b7a26572629196d17512da745b41b29658067c24cdf035eeb409cb1e7a4e76c03f147282e
SHA1 hash: 28cff4da385a84cfa71d452674b3fb47d5c480ff
MD5 hash: dc7d0a2b5e14e1de962a26210383d578
humanhash: kansas-charlie-quebec-pizza
File name:Payment_MT_103_776363_Swift_Confirmation.xz
Download: download sample
Signature RemcosRAT
File size:32'294 bytes
First seen:2021-03-04 07:24:35 UTC
Last seen:Never
File type: xz
MIME type:application/x-rar
ssdeep 768:3VDOhJe9hHKsjHWBe4VTaf5Z2HAUggy8Vg:3Vane7HPjHK5YS7K
TLSH 44E2E1356941D3402E8B37876A7B5E290C6C7D9CE378016008B765C7879DCFD6AABC1E
Reporter abuse_ch
Tags:RAT RemcosRAT xz


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: mail.jetmails.xyz
Sending IP: 103.109.37.166
From: account <admin@jetmails.xyz>
Subject: Re: Payment Advice(MT103) TT/USD/2021
Attachment: Payment_MT_103_776363_Swift_Confirmation.xz (contains "Payment_MT_103_#776363_Swift_Confirmation.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
318
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

xz 414641c411715dd041c11c11b0b935944b920be200bab08fe537edefc5c6d4b7

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments