MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49b7a81c8c9154b42d564348b3a2a93be94bf14de11809e823891fafb65c113f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 49b7a81c8c9154b42d564348b3a2a93be94bf14de11809e823891fafb65c113f
SHA3-384 hash: e331356b6770b5de3dc7a449ac9779292725144878da4ee6199ca4c8f7a1c00c707839adb04b6674937c4d2c0ae8b32e
SHA1 hash: a6f10de382a056916929d81c978e675932e3158c
MD5 hash: d12c64d45cd7416cc3a3ee41cc81083a
humanhash: quiet-whiskey-apart-thirteen
File name:Wjhus order 13.1.2021.gz
Download: download sample
Signature RemcosRAT
File size:217'591 bytes
First seen:2021-01-13 07:40:54 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 6144:I7XIttUjMfyjLRxKP9Zpx8OCAY7M6gL/bXybd5dDJ1axP+:ITlAfyjLfKVbuOYFgLTibdv7axP+
TLSH 852412DF0D4250EA8D85E71E38ABEABA7CF5543481F76B0F8533522BBADC45168E4138
Reporter abuse_ch
Tags:gz


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: gmkey.mywire.org
Sending IP: 23.254.227.72
From: Rebecca F. Precia <rebecca@wjhuis.top>
Subject: new order for Wjhus - 13.01.2021
Attachment: Wjhus order 13.1.2021.gz (contains "Wjhus order 13.1.2021.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2021-01-13 06:04:38 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

gz 49b7a81c8c9154b42d564348b3a2a93be94bf14de11809e823891fafb65c113f

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments