🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4d12b9dc3abe7b7660828ee452e411a0acb0a57beb81e7dcb23d5ccec175bfdb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 4d12b9dc3abe7b7660828ee452e411a0acb0a57beb81e7dcb23d5ccec175bfdb
SHA3-384 hash: 97d7a94b873334d61904d5383810833c7493fb51c03a5a28fe387ff2a4910fdf1885776fadb131d0a5a9d8a6c812b50d
SHA1 hash: bf04ccc43d57a6ba158dd32dbe8b2fc69539ecbc
MD5 hash: 6cc798249343310071329f2505937c24
humanhash: princess-mobile-moon-sodium
File name:Booking Information.7z
Download: download sample
Signature RemcosRAT
File size:551'250 bytes
First seen:2023-02-28 10:21:31 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 12288:RdTnS1n+PufdX3qYEw06ydo2gQwsAcGGGKWp6d3p9iA:fTnS1+eXj0Pd2EGGpzviA
TLSH T192C4F1253F5887FF41D6E245CE27EC0C6B507E7E8858B6EAB3D65BCB0688805BC16835
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter 0xToxin
Tags:7z agoziem ezeife-kozow-com file-pumped remcos RemcosRAT


Avatar
0xToxin
contains 300MB .NET loader:
2ca77ae4e69f709ffad466371d787c88a7610344e3ae2984292d70e4de986396

drops remcos:
3af3cffefa2df2c079f2901470005de5c361357e1072fd234226d72ea2214d45

Intelligence


File Origin
# of uploads :
1
# of downloads :
142
Origin country :
IL IL
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:Booking Information.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:314'572'800 bytes
SHA256 hash: 2ca77ae4e69f709ffad466371d787c88a7610344e3ae2984292d70e4de986396
MD5 hash: 124667e86f33d2489a6c3fb5f3175716
De-pumped file size:727'552 bytes (Vs. original size of 314'572'800 bytes)
De-pumped SHA256 hash: 8281bd35f26f5b9b6984ecd58c5a2f6024858f7524c432230a36b5ddf4be1bf9
De-pumped MD5 hash: 0b87d792487c3c31f328bbc2ca30bd94
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-vm barys large-file obfuscated overlay packed
Threat name:
ByteCode-MSIL.Trojan.Hulk
Status:
Malicious
First seen:
2023-02-28 11:16:13 UTC
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments