MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 78b75b6b9d255c96267433936c42e3a66cfe733280483ba5658598cb021786da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 78b75b6b9d255c96267433936c42e3a66cfe733280483ba5658598cb021786da
SHA3-384 hash: af521401b431d83d06ddce8bfff77d9232eb85cdea7206dd838fcb8b4fae849c9bd017c48b9ef0c808e77aa06ab2fa36
SHA1 hash: 5e9bfdc11bbaecb2ac4d3ca27b1d701e1ad56888
MD5 hash: 83af5fbadb27f44750b760eda3ab6518
humanhash: mississippi-network-maryland-wyoming
File name:0900900.uue
Download: download sample
Signature RemcosRAT
File size:114'133 bytes
First seen:2021-04-15 05:47:35 UTC
Last seen:2021-04-15 06:01:59 UTC
File type: zip
MIME type:application/zip
ssdeep 3072:uYF5Rhr/5RhPaYxyg3c8+7DYlQI91kkKwuIOwl1:Jb5jzyGc8+XmrWdwD
TLSH A0B302A9200AAFCC4CF1E23A06F6D21EE997796EE04904557E10A5C7C1ECA496FFC497
Reporter lowmal3
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
4
# of downloads :
123
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Predator
Status:
Malicious
First seen:
2021-04-15 04:05:50 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
11 of 47 (23.40%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos rat
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Loads dropped DLL
Remcos
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip 78b75b6b9d255c96267433936c42e3a66cfe733280483ba5658598cb021786da

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments