MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 491cff43b259addd44a312094b15674d2c33c9ab901500130fead03e7d9d6530. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 491cff43b259addd44a312094b15674d2c33c9ab901500130fead03e7d9d6530
SHA3-384 hash: e21846cac572282c4afca2b0ee769722d0196d8831092e446f6627baf5131c1600f79739465dfb3631c2bb8091cd8adc
SHA1 hash: 686ca5b3fdb1606769054107783ab4ad49a3acec
MD5 hash: 0c6a22a028ce02e10608bb44b7b4c66f
humanhash: king-mexico-venus-sad
File name:SecuriteInfo.com.Artemis0C6A22A028CE.16359
Download: download sample
Signature RemcosRAT
File size:1'528'320 bytes
First seen:2020-07-10 12:10:52 UTC
Last seen:2020-07-11 06:55:31 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 67b246f5bc27b6a1b537c01e50aff789 (3 x RemcosRAT, 3 x AveMariaRAT, 1 x ParallaxRAT)
ssdeep 12288:QdNBlWS3MVbDQmQQSzZEjBcoIdGmYbUxjq:IbvcbDQmQzGjz2GnbC
Threatray 826 similar samples on MalwareBazaar
TLSH 55657D22F2D18537F16A1A79CC4B97A85839BDD33D24EC463BE83D0C5F39681782A197
Reporter SecuriteInfoCom
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
3
# of downloads :
83
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Creating a window
DNS request
Sending a custom TCP request
Launching the default Windows debugger (dwwin.exe)
Threat name:
Win32.Trojan.RemcosCrypt
Status:
Malicious
First seen:
2020-07-10 10:15:18 UTC
File Type:
PE (Exe)
Extracted files:
75
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
persistence rat family:remcos
Behaviour
Suspicious use of WriteProcessMemory
Modifies registry key
Suspicious use of SetThreadContext
Legitimate hosting services abused for malware hosting/C2
Adds Run entry to start application
Executes dropped EXE
Remcos
Malware Config
C2 Extraction:
karimgoussd.ug:6969
fgdjhksdfsdxcbv.ru:6969
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

Executable exe 491cff43b259addd44a312094b15674d2c33c9ab901500130fead03e7d9d6530

(this sample)

  
Delivery method
Distributed via web download

Comments