MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 58041c57728dd0597d3d009fcf902df1d9b9910b8b49b8021695344573da9885. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 58041c57728dd0597d3d009fcf902df1d9b9910b8b49b8021695344573da9885
SHA3-384 hash: bedd116b46fefd9ec3f7fc0cd79b57b50f8a7e4a2f0c4382aba053c069df2edb7428d6c0b05a2d168997a34177cba398
SHA1 hash: 72e6078314587b84fe9f7823ff1c7fb40802f422
MD5 hash: 62ea41aa602bd4f7cea53401b0738636
humanhash: idaho-helium-mango-fish
File name:Hormann Mexico SA de CV- Nuevo pedido.iso
Download: download sample
Signature RemcosRAT
File size:1'081'344 bytes
First seen:2021-02-10 16:54:44 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:q82glUZCAYAIo4Kv8dSF8f+W2RoVep9J7dEtOw8Ps1j:R2oWPIo9v8de5+efdm78Pkj
TLSH 4A357DF17BA14437E0133ABA9C5A53A469263DA8695C484EB7B4FE0A7F357853CC804F
Reporter abuse_ch
Tags:iso RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: server.doole.io
Sending IP: 188.40.83.134
From: Zavala Cristian <cotizacion.mty@hormann.com.mx>
Subject: RE: Hormann Mexico SA de CV- Nuevo pedido
Attachment: Hormann Mexico SA de CV- Nuevo pedido.iso (contains "Hormann Mexico SA de CV- Nuevo pedido.exe")

RemcosRAT C2:
marstonstyl247.ddns.net:8364

Intelligence


File Origin
# of uploads :
1
# of downloads :
157
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Infostealer.Fareit
Status:
Malicious
First seen:
2021-02-10 15:48:03 UTC
AV detection:
14 of 45 (31.11%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

iso 58041c57728dd0597d3d009fcf902df1d9b9910b8b49b8021695344573da9885

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments