MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 49b7a81c8c9154b42d564348b3a2a93be94bf14de11809e823891fafb65c113f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 3
| SHA256 hash: | 49b7a81c8c9154b42d564348b3a2a93be94bf14de11809e823891fafb65c113f |
|---|---|
| SHA3-384 hash: | e331356b6770b5de3dc7a449ac9779292725144878da4ee6199ca4c8f7a1c00c707839adb04b6674937c4d2c0ae8b32e |
| SHA1 hash: | a6f10de382a056916929d81c978e675932e3158c |
| MD5 hash: | d12c64d45cd7416cc3a3ee41cc81083a |
| humanhash: | quiet-whiskey-apart-thirteen |
| File name: | Wjhus order 13.1.2021.gz |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 217'591 bytes |
| First seen: | 2021-01-13 07:40:54 UTC |
| Last seen: | Never |
| File type: | gz |
| MIME type: | application/x-rar |
| ssdeep | 6144:I7XIttUjMfyjLRxKP9Zpx8OCAY7M6gL/bXybd5dDJ1axP+:ITlAfyjLfKVbuOYFgLTibdv7axP+ |
| TLSH | 852412DF0D4250EA8D85E71E38ABEABA7CF5543481F76B0F8533522BBADC45168E4138 |
| Reporter | |
| Tags: | gz |
abuse_ch
Malspam distributing unidentified malware:HELO: gmkey.mywire.org
Sending IP: 23.254.227.72
From: Rebecca F. Precia <rebecca@wjhuis.top>
Subject: new order for Wjhus - 13.01.2021
Attachment: Wjhus order 13.1.2021.gz (contains "Wjhus order 13.1.2021.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
169
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Dropper.Generic
Status:
Suspicious
First seen:
2021-01-13 06:04:38 UTC
AV detection:
11 of 46 (23.91%)
Threat level:
3/5
Detection(s):
Suspicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Legit
Score:
0.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.