🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 56ea9fe1dca86705d54c6b65864dee27ae1e1725661ee7d2fd812d1b19fae7fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 56ea9fe1dca86705d54c6b65864dee27ae1e1725661ee7d2fd812d1b19fae7fc
SHA3-384 hash: f8856cf215201565fed5cbb5f4707992f2f7bd25ce3ec86f452536f0ea0bb0e70a8ecb5777e41e9a36da641a45312ec6
SHA1 hash: af20057fbd710ef27ba86fadecf4e5d1be30b709
MD5 hash: 97ecc3eb3fc995d85a6b69f918e93934
humanhash: steak-muppet-south-potato
File name:DOCUMENTO TRANSACCION DIGITAL.tar
Download: download sample
Signature RemcosRAT
File size:1'350'537 bytes
First seen:2023-03-31 09:59:34 UTC
Last seen:Never
File type: tar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 3034
ssdeep 24576:HHiySCnJFMNaz7mc9Mg/GPDl6WELv8gOygkBet0xrdtPslU79S3P5fr8MDod1mo:nNbn7tCc9MoWUPv8rkBxZtPsmU3VrZDo
TLSH T1AF55337CC47DE8298B575DE68032B35C918D681B012EDFCB9CF59C72E62268EE0C654E
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter JAMESWT_WT
Tags:file-pumped pw-3034 remcos RemcosRAT tar werverdsfefef-con-ip-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
138
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:DOCUMENTO TRANSACCION DIGITAL.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:1'153'433'600 bytes
SHA256 hash: 4485b21944368a70b1a7cfb2c4956f734263eae8ea92674fed025515496c914e
MD5 hash: 256ec61ef715ea680575922a1a856dc6
De-pumped file size:615'936 bytes (Vs. original size of 1'153'433'600 bytes)
De-pumped SHA256 hash: 45b64ce6904093116010053f0cc3a72f63efa96d0ab3fed7dd343a6c7f3d8d6c
De-pumped MD5 hash: ddfb2f242e5a78b0a1e2f059e153a0ea
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:mexico rat
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Remcos
Malware Config
C2 Extraction:
werverdsfefef.con-ip.com:1883
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments