🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49cf050274b9a52bf56ac45d548d91c5a13c6d65c36bf363447ffa3f0143c078. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 49cf050274b9a52bf56ac45d548d91c5a13c6d65c36bf363447ffa3f0143c078
SHA3-384 hash: 3c9d0de4f9f30df8bcd20b1d15381525f1de2e79a3c3d3da0f92ee50824723108ed0522ece21a2766dc372fbc26e5b2e
SHA1 hash: 1d3d5576790a9c72ddb03eaacac1bddd25d77477
MD5 hash: a9749727f9641b10363c264695ce4822
humanhash: seven-minnesota-pasta-alpha
File name:Enquiry 230424.bat
Download: download sample
Signature RemcosRAT
File size:4'541'520 bytes
First seen:2024-04-23 12:19:40 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 49152:yEi0F7JFavH5JDy0oqMaKcCln2UE+EMKyGY6i6KyGY6i6KyGY6i6KyGY6i6KyGYO:I
TLSH T15B26B6E33DAF16CA9705736B974FE5240A1BCC240BC2DFEC50E69588580BF5B2990F5A
Reporter lowmal3
Tags:bat remcos RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
115
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  10/10
Confidence:
100%
Tags:
masquerade
Result
Threat name:
Remcos, DBatLoader
Detection:
malicious
Classification:
rans.bank.troj.spyw.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Detected Remcos RAT
Drops or copies certutil.exe with a different name (likely to bypass HIPS)
Drops or copies cmd.exe with a different name (likely to bypass HIPS)
Drops PE files to the user root directory
Drops PE files with a suspicious file extension
Found large BAT file
Found malware configuration
Installs a global keyboard hook
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Registers a new ROOT certificate
Sigma detected: Execution from Suspicious Folder
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Parent in Public Folder Suspicious Process
Sigma detected: Remcos
Sigma detected: Suspicious Program Location with Network Connections
Uses dynamic DNS services
Yara detected DBatLoader
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1430840 Sample: Enquiry 230424.bat Startdate: 24/04/2024 Architecture: WINDOWS Score: 100 63 officerem.duckdns.org 2->63 65 ip.2007.filemail.com 2->65 67 2007.filemail.com 2->67 83 Multi AV Scanner detection for domain / URL 2->83 85 Found malware configuration 2->85 87 Malicious sample detected (through community Yara rule) 2->87 91 12 other signatures 2->91 9 cmd.exe 1 2->9         started        11 Rwksdoeb.PIF 2->11         started        14 Rwksdoeb.PIF 2->14         started        signatures3 89 Uses dynamic DNS services 63->89 process4 signatures5 16 sppsvc.pif 4 10 9->16         started        21 extrac32.exe 1 9->21         started        23 alpha.exe 1 9->23         started        25 5 other processes 9->25 93 Multi AV Scanner detection for dropped file 11->93 95 Contains functionality to bypass UAC (CMSTPLUA) 11->95 97 Detected Remcos RAT 11->97 99 5 other signatures 11->99 process6 dnsIp7 57 officerem.duckdns.org 23.95.235.29, 47212 AS-COLOCROSSINGUS United States 16->57 59 127.0.0.1 unknown unknown 16->59 61 ip.2007.filemail.com 50.7.84.74, 443, 49704, 49705 COGENT-174US United States 16->61 41 C:\Users\Public\Libraries\netutils.dll, PE32+ 16->41 dropped 43 C:\Users\Public\Libraries\easinvoker.exe, PE32+ 16->43 dropped 45 C:\Users\Public\Rwksdoeb.url, MS 16->45 dropped 49 2 other malicious files 16->49 dropped 69 Multi AV Scanner detection for dropped file 16->69 71 Detected Remcos RAT 16->71 73 Contains functionalty to change the wallpaper 16->73 81 4 other signatures 16->81 27 extrac32.exe 1 16->27         started        31 cmd.exe 1 16->31         started        47 C:\Users\Public\alpha.exe, PE32+ 21->47 dropped 75 Drops PE files to the user root directory 21->75 77 Drops or copies certutil.exe with a different name (likely to bypass HIPS) 21->77 79 Drops or copies cmd.exe with a different name (likely to bypass HIPS) 21->79 33 kn.exe 3 2 23->33         started        35 kn.exe 2 25->35         started        37 extrac32.exe 1 25->37         started        file8 signatures9 process10 file11 51 C:\Users\Public\Libraries\Rwksdoeb.PIF, PE32 27->51 dropped 39 conhost.exe 31->39         started        101 Registers a new ROOT certificate 33->101 103 Drops PE files with a suspicious file extension 33->103 53 C:\Users\Public\Libraries\sppsvc.pif, PE32 35->53 dropped 55 C:\Users\Public\kn.exe, PE32+ 37->55 dropped signatures12 process13
Threat name:
Win32.Trojan.Sonbokli
Status:
Malicious
First seen:
2024-04-23 11:59:40 UTC
File Type:
Text
Extracted files:
1
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

Batch (bat) bat 49cf050274b9a52bf56ac45d548d91c5a13c6d65c36bf363447ffa3f0143c078

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments