🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75caad097967fac651646c4275a3554c61d25de347e367d7a75ee3d95fd61a85. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 75caad097967fac651646c4275a3554c61d25de347e367d7a75ee3d95fd61a85
SHA3-384 hash: 1f27c8b2e3a3bc00a7d2992d5da1e739e51313b3e42614eb79197aa6de9479f63219de606c8021a42e7f1445bd820491
SHA1 hash: 10d9fd7999aa384050268ab9bbbd662229997622
MD5 hash: 46f2df42e70a812c080bcb9756d6e415
humanhash: echo-steak-bluebird-stream
File name:DOCUMENTO TRANSACCION DIGITAL(1) pw9303.tar
Download: download sample
Signature RemcosRAT
File size:1'298'617 bytes
First seen:2023-03-31 09:19:56 UTC
Last seen:Never
File type: tar
MIME type:application/x-rar
Note:This file is a password protected archive. The password is: 9303
ssdeep 24576:DojWYGfW3u2bdWgBOdLM/Bg0s6TANp8UzBAjZlVJh5gse1KQ/GYSuL:DSGfW3u218LM60s6T4GlLgse1KQuJc
TLSH T15F5533E7EBC1F6883C49259E82589D285D8FF1109C2167F2C264EF042ED914D4EFDA6B
TrID 58.3% (.RAR) RAR compressed archive (v-4.x) (7000/1)
41.6% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter JAMESWT_WT
Tags:file-pumped pw-9303 remcos RemcosRAT tar werverdsfefef-con-ip-com

Intelligence


File Origin
# of uploads :
1
# of downloads :
134
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:DOCUMENTO TRANSACCION DIGITAL.exe
Pumped file This file is pumped. MalwareBazaar has de-pumped it.
File size:1'153'433'600 bytes
SHA256 hash: ae19d903d29fdcde771c606432489108d135b583a18044fc6acdb9664e5c32a0
MD5 hash: 17f416669c23c77cb3811ea9e2108ddd
De-pumped file size:574'464 bytes (Vs. original size of 1'153'433'600 bytes)
De-pumped SHA256 hash: 94cedf6da0733595d75621ccc50d53136ddd9239e447b6d9fdbd4697f3d4814f
De-pumped MD5 hash: 9f60a516c98b4d72b4975ec4b9b5b53f
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:mexico rat
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Drops file in System32 directory
Suspicious use of SetThreadContext
Checks computer location settings
Executes dropped EXE
Remcos
Malware Config
C2 Extraction:
werverdsfefef.con-ip.com:1883
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RemcosRAT

tar 75caad097967fac651646c4275a3554c61d25de347e367d7a75ee3d95fd61a85

(this sample)

  
Delivery method
Distributed via web download

Comments