MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 6a6a6a9b2aacf2d9160c9fbf3d4addcb93f7d7b9d13a7d7bcecbd33777ffc153. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 4
| SHA256 hash: | 6a6a6a9b2aacf2d9160c9fbf3d4addcb93f7d7b9d13a7d7bcecbd33777ffc153 |
|---|---|
| SHA3-384 hash: | 476a0cf59407ecedc45e308dbbf85603990ae672aec811b8b086294a275ab7a463672037f36efeb1d09ff9680c4ea304 |
| SHA1 hash: | 3fc284f7c28cdbf0764a572e63f020d59321ada7 |
| MD5 hash: | 6dd305d7b517434d31ed75b706c061fd |
| humanhash: | helium-hawaii-uniform-xray |
| File name: | d88e07467ddcf9e3b19fa972b9f000d1.gz |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 629'248 bytes |
| First seen: | 2021-02-19 11:00:00 UTC |
| Last seen: | Never |
| File type: | tar |
| MIME type: | application/x-tar |
| ssdeep | 12288:Xv6GE26ZFEQgy6U4pslkXkkE+oApCJWX0iSxevT:f6GReF2yZssgXp8WX0FxK |
| TLSH | E1D4BD0172A88F1AE03A47F95421A61453F5BB99783ED78D8DE2B4EF3B72F808D01653 |
| Reporter | |
| Tags: | gz RAT RemcosRAT |
abuse_ch
Malspam distributing RemcosRAT:HELO: slot0.groveressentials.xyz
Sending IP: 203.159.80.67
From: Sales16 - PCMT <order@groveressentials.xyz>
Subject: Inquiry/2021/FEB-019/QUOTATION 20210219 PURCHASE ORDER (НОВЫЙ ЗАКАЗ)
Attachment: d88e07467ddcf9e3b19fa972b9f000d1.gz (contains "d88e07467ddcf9e3b19fa972b9f000d1.exe")
RemcosRAT C2:
sandshoe.myfirewall.org
Intelligence
File Origin
# of uploads :
1
# of downloads :
284
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-02-19 11:00:08 UTC
AV detection:
2 of 48 (4.17%)
Threat level:
5/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Backdoor
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
RemcosRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.