MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 43987e781d3195cb2d75e0a9acca5de1cbd7eefd2010cce9afd897d5e8c9f594. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 43987e781d3195cb2d75e0a9acca5de1cbd7eefd2010cce9afd897d5e8c9f594
SHA3-384 hash: a0c8b57fd015905cc64e2da6ab956e6997226e45ac02f0be8314c845a2ea6e34f21c485665c397627bd8de62da41882d
SHA1 hash: 44d2696a0a31ce7c15553bf88e1605e67a4e6545
MD5 hash: 403e27e527baabeb53ef83b99c4cadee
humanhash: pip-snake-bravo-lake
File name:Recievable_Advise_Part1.pdf
Download: download sample
Signature RemcosRAT
File size:36'017 bytes
First seen:2024-12-16 13:36:25 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 768:+RQMQlUEVtWDv/2MpXBrm6fA6Gx9Tq2fTxvHMWkRLS:cmlNVW2GXBA6A/vHMC
TLSH T13EF2E01A95BC86E2D8804AF7DD08D7135994019DA6B61AA72A2D8F8170FEC94FC07FD3
Magika pdf
Reporter smica83
Tags:pdf remcos RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
541
Origin country :
HU HU
Vendor Threat Intelligence
Verdict:
Malicious
Score:
81.4%
Tags:
virus
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
form phishing
Label:
Malicious
Suspicious Score:
8.0/10
Score Malicious:
81%
Score Benign:
19%
Result
Threat name:
n/a
Detection:
suspicious
Classification:
n/a
Score:
20 / 100
Signature
AI detected landing page (webpage, office document or email)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1576092 Sample: Recievable_Advise_Part1.pdf Startdate: 16/12/2024 Architecture: WINDOWS Score: 20 20 x1.i.lencr.org 2->20 22 bg.microsoft.map.fastly.net 2->22 34 AI detected landing page (webpage, office document or email) 2->34 8 chrome.exe 1 2->8         started        11 Acrobat.exe 18 71 2->11         started        signatures3 process4 dnsIp5 24 192.168.2.4, 138, 443, 49645 unknown unknown 8->24 26 239.255.255.250 unknown Reserved 8->26 13 chrome.exe 8->13         started        16 AcroCEF.exe 101 11->16         started        process6 dnsIp7 28 www.google.com 142.250.181.68, 443, 49759, 49849 GOOGLEUS United States 13->28 30 ip.2012.filemail.com 50.7.224.146, 443, 49754, 49755 COGENT-174US United States 13->30 32 2012.filemail.com 13->32 18 AcroCEF.exe 4 16->18         started        process8
Threat name:
Document-PDF.Dropper.Heuristic
Status:
Malicious
First seen:
2024-12-16 04:21:49 UTC
File Type:
Document
Extracted files:
7
AV detection:
6 of 38 (15.79%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Sus_Obf_Enc_Spoof_Hide_PE
Author:XiAnzheng
Description:Check for Overlay, Obfuscating, Encrypting, Spoofing, Hiding, or Entropy Technique(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments