MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6a6a6a9b2aacf2d9160c9fbf3d4addcb93f7d7b9d13a7d7bcecbd33777ffc153. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 6a6a6a9b2aacf2d9160c9fbf3d4addcb93f7d7b9d13a7d7bcecbd33777ffc153
SHA3-384 hash: 476a0cf59407ecedc45e308dbbf85603990ae672aec811b8b086294a275ab7a463672037f36efeb1d09ff9680c4ea304
SHA1 hash: 3fc284f7c28cdbf0764a572e63f020d59321ada7
MD5 hash: 6dd305d7b517434d31ed75b706c061fd
humanhash: helium-hawaii-uniform-xray
File name:d88e07467ddcf9e3b19fa972b9f000d1.gz
Download: download sample
Signature RemcosRAT
File size:629'248 bytes
First seen:2021-02-19 11:00:00 UTC
Last seen:Never
File type: tar
MIME type:application/x-tar
ssdeep 12288:Xv6GE26ZFEQgy6U4pslkXkkE+oApCJWX0iSxevT:f6GReF2yZssgXp8WX0FxK
TLSH E1D4BD0172A88F1AE03A47F95421A61453F5BB99783ED78D8DE2B4EF3B72F808D01653
Reporter abuse_ch
Tags:gz RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: slot0.groveressentials.xyz
Sending IP: 203.159.80.67
From: Sales16 - PCMT <order@groveressentials.xyz>
Subject: Inquiry/2021/FEB-019/QUOTATION 20210219 PURCHASE ORDER (НОВЫЙ ЗАКАЗ)
Attachment: d88e07467ddcf9e3b19fa972b9f000d1.gz (contains "d88e07467ddcf9e3b19fa972b9f000d1.exe")

RemcosRAT C2:
sandshoe.myfirewall.org

Intelligence


File Origin
# of uploads :
1
# of downloads :
284
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Pwsx
Status:
Malicious
First seen:
2021-02-19 11:00:08 UTC
AV detection:
2 of 48 (4.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

tar 6a6a6a9b2aacf2d9160c9fbf3d4addcb93f7d7b9d13a7d7bcecbd33777ffc153

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments