🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 57ad4237be228935df14ea78a2f0ddff450d621541316ef06d043e962b9c8d66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 6


Intelligence 6 IOCs YARA 7 File information Comments

SHA256 hash: 57ad4237be228935df14ea78a2f0ddff450d621541316ef06d043e962b9c8d66
SHA3-384 hash: f39de6980e620381e75226d5827e70773701e3626ab231a01d048ce9f43eefdcaeb594ad6d64b324b14b2d7491a7eba4
SHA1 hash: 08924b6f72c9729b4195bfc4d0181e869a17508d
MD5 hash: d369e18ec4048062a567171eeae2cecd
humanhash: pip-cold-speaker-nitrogen
File name:AWB, Commercial Invoice, Bill of Lading & Parkinglist_pdf.img
Download: download sample
Signature RemcosRAT
File size:1'245'184 bytes
First seen:2023-06-27 13:04:21 UTC
Last seen:2023-06-29 06:56:35 UTC
File type: img
MIME type:application/x-iso9660-image
ssdeep 6144:nYa6lYz84WE8fYunZTkHvZjzuaadQOACZx7vhTTFgARS0K2zYN9mNNn17M7Qsxst:nYQz8Y8RToZxai2R5g8uXmNfGA
TLSH T188452261EBA5C0A7E1F665702A34622F25F2F06310B9075B73DC962CAB47BA0DD1F712
TrID 50.6% (.ISO/UDF) UDF disc image (2114500/1/6)
49.0% (.NULL) null bytes (2048000/1)
0.1% (.ATN) Photoshop Action (5007/6/1)
0.0% (.ISO) ISO 9660 CD image (2545/36/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
Reporter malwarelabnet
Tags:img remcos RemcosRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
120
Origin country :
CA CA
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:AWB__COM.EXE
File size:495'629 bytes
SHA256 hash: 7cd77a765069b1826b7594f693608500096f6f902c25b7994fa4d58bfe91be66
MD5 hash: 98d52c27d53e81ace5db2d1b1580f6e8
MIME type:application/x-dosexec
Signature RemcosRAT
File name:AWB__COM.PDF
File size:510 bytes
SHA256 hash: e1465dddef5069ae5ebb4889660441e04bb189f658fe6199c1210f92474368cf
MD5 hash: 3d41dc1211e95e3ebd06b2181765f48e
MIME type:application/pdf
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
context-iso lolbin overlay packed remcos shell32.dll
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2023-06-26 19:26:51 UTC
File Type:
Binary (Archive)
Extracted files:
6
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:iexplorer_remcos
Author:iam-py-test
Description:Detect iexplorer being taken over by Remcos
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:Remcos
Author:kevoreilly
Description:Remcos Payload
Rule name:REMCOS_RAT_variants
Rule name:shellcode
Author:nex
Description:Matched shellcode byte patterns
Rule name:Windows_Trojan_Remcos_b296e965
Author:Elastic Security
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments