MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 41e3f963ff93e6201db06abd392b2ad85796a86de7f67f5a9932b55e0e237405. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 41e3f963ff93e6201db06abd392b2ad85796a86de7f67f5a9932b55e0e237405
SHA3-384 hash: f41d06f4f2f015e0e7281f294e4da0eb621ac2f04f9e4a14d8d327e55af0da13e1abc047fd82497a4744d2fbb9930452
SHA1 hash: 698fd5403af756d9e4bb94ff648fe6698fe06585
MD5 hash: 36c88c74a5e6fb76835a3e5d1cc1ee71
humanhash: montana-nevada-december-burger
File name:Synimed PO11122019.zip
Download: download sample
Signature RemcosRAT
File size:398'976 bytes
First seen:2020-06-26 11:57:41 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:T/BF3+kxd6VmbN508ZuKijIoIqXzT1LaWi1rUbSz+CH/NskZtZ4:TH3+in/IRjRni1rUbjCH/LS
TLSH 8184232CCC65B33A14C2F7A66A8CD8F359A99C36DE2BD1368E21DF5171E9D09211B027
Reporter abuse_ch
Tags:nVpn RAT RemcosRAT zip


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: corporate.orangemali.net
Sending IP: 197.155.141.42
From: MATHIEU GONÇALVES <synimed@synimed.com>
Subject: Synimed PO11122019
Attachment: Synimed PO11122019.zip (contains "Synimed PO11122019.exe")

RemcosRAT C2:
jamesanderson68986.ddns.net:1965 (194.5.98.23)

Pointing to nVpn:

% Information related to '194.5.98.0 - 194.5.98.255'

% Abuse contact for '194.5.98.0 - 194.5.98.255' is 'abuse@inter-cloud.tech'

inetnum: 194.5.98.0 - 194.5.98.255
netname: Privacy_Online
descr: Longyearbyen, Svalbard und Jan Mayen
country: SJ
admin-c: RA9926-RIPE
tech-c: RA9926-RIPE
org: ORG-NFAS6-RIPE
status: ASSIGNED PA
mnt-by: inter-cloud-mnt
created: 2019-04-26T16:42:54Z
last-modified: 2020-03-13T23:11:55Z
source: RIPE

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Delf
Status:
Malicious
First seen:
2020-06-26 11:59:03 UTC
AV detection:
16 of 48 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip 41e3f963ff93e6201db06abd392b2ad85796a86de7f67f5a9932b55e0e237405

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments