MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49cdd7de1221f673cbf2cf8c51c3e2728984352e5964cae1b3010740e236eb46. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 49cdd7de1221f673cbf2cf8c51c3e2728984352e5964cae1b3010740e236eb46
SHA3-384 hash: 2e720ca93c5db62f8ce6ef13c64a597ba1c73ba6dbe76f16cc48e1c41d6764f5f2f96a52d1ec5f03ea080be89ab9081c
SHA1 hash: d8cc994dbd0af0f078377d884ca594ad17b997a7
MD5 hash: 74efa7497a26b6d84b3fc05c92ba272e
humanhash: eight-leopard-ack-mirror
File name:74efa7497a26b6d84b3fc05c92ba272e.exe
Download: download sample
Signature RemcosRAT
File size:141'553 bytes
First seen:2021-07-10 08:06:51 UTC
Last seen:2021-07-10 08:39:13 UTC
File type:Executable exe
MIME type:application/x-dosexec
ssdeep 3072:7H8L123BjQNWewAsAYu7t1UNsISClSwBidtqmBIuPSbWT5ieKiwb6ooa1hhiQ:7H8Lyh5Wt60IaBTFKiwb6ooaX
TLSH T179D35C3AF5C1C83BC1629D78DD0A9158F419BEE13E1824477BED9D899B3F39275280C6
Reporter abuse_ch
Tags:exe RAT RemcosRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
281
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
74efa7497a26b6d84b3fc05c92ba272e.exe
Verdict:
No threats detected
Analysis date:
2021-07-10 08:09:16 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
unknown
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
49cdd7de1221f673cbf2cf8c51c3e2728984352e5964cae1b3010740e236eb46
MD5 hash:
74efa7497a26b6d84b3fc05c92ba272e
SHA1 hash:
d8cc994dbd0af0f078377d884ca594ad17b997a7
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

Executable exe 49cdd7de1221f673cbf2cf8c51c3e2728984352e5964cae1b3010740e236eb46

(this sample)

  
Delivery method
Distributed via web download

Comments