MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 18


Intelligence 18 IOCs YARA 29 File information Comments

SHA256 hash: 8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
SHA3-384 hash: 3808fdb8d7779e29203d6c42a5c869dc25eb9bc4ca5785c20b5f2057e026b45a73aed289deaee7f7ee5c64fe314ac3d4
SHA1 hash: 7e3eba28bc4b89801c91de5450aa28da5c6ff941
MD5 hash: 636a54861ddd167065f294cc76fca7ba
humanhash: uniform-bakerloo-alabama-cardinal
File name:SecuriteInfo.com.Win32.PWSX-gen.22684.1131
Download: download sample
Signature RemcosRAT
File size:913'408 bytes
First seen:2024-04-05 13:24:35 UTC
Last seen:2024-04-06 10:07:56 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'742 x AgentTesla, 19'607 x Formbook, 12'242 x SnakeKeylogger)
ssdeep 24576:GgkHhAVqHxUrlWy05hMud6hHERSIhO0RDP+dB8:I2V+Ur6MIMHERSIQ0RDr
Threatray 2'199 similar samples on MalwareBazaar
TLSH T19C1523003385FB5BD97ED7FD552A680193B15F8AB992E2489DC225CB4371B808B6DF43
TrID 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
10.2% (.EXE) Win64 Executable (generic) (10523/12/4)
6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.3% (.EXE) Win32 Executable (generic) (4504/4/1)
2.0% (.ICL) Windows Icons Library (generic) (2059/9)
Reporter SecuriteInfoCom
Tags:exe RemcosRAT

Intelligence


File Origin
# of uploads :
4
# of downloads :
327
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c.exe
Verdict:
Malicious activity
Analysis date:
2024-04-05 13:37:45 UTC
Tags:
rat remcos remote keylogger

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a process with a hidden window
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
DNS request
Connection attempt
Creating a file in the %AppData% subdirectories
Sending a custom TCP request
Sending an HTTP GET request
Reading critical registry keys
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade packed remcos
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
rans.phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Detected Remcos RAT
Found malware configuration
Injects a PE file into a foreign processes
Installs a global keyboard hook
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Remcos
Sigma detected: Scheduled temp file as task from temp location
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes many files with high entropy
Yara detected AntiVM3
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1420900 Sample: SecuriteInfo.com.Win32.PWSX... Startdate: 05/04/2024 Architecture: WINDOWS Score: 100 58 paygateme.net 2->58 60 geoplugin.net 2->60 72 Multi AV Scanner detection for domain / URL 2->72 74 Found malware configuration 2->74 76 Malicious sample detected (through community Yara rule) 2->76 78 12 other signatures 2->78 8 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 7 2->8         started        12 tzRVJJzEigd.exe 5 2->12         started        signatures3 process4 file5 46 C:\Users\user\AppData\...\tzRVJJzEigd.exe, PE32 8->46 dropped 48 C:\Users\user\AppData\Local\...\tmpF6F8.tmp, XML 8->48 dropped 80 Tries to steal Mail credentials (via file registry) 8->80 82 Uses schtasks.exe or at.exe to add and modify task schedules 8->82 84 Adds a directory exclusion to Windows Defender 8->84 92 2 other signatures 8->92 14 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 3 1014 8->14         started        19 powershell.exe 23 8->19         started        21 schtasks.exe 1 8->21         started        23 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 8->23         started        86 Multi AV Scanner detection for dropped file 12->86 88 Contains functionality to bypass UAC (CMSTPLUA) 12->88 90 Contains functionalty to change the wallpaper 12->90 94 5 other signatures 12->94 25 tzRVJJzEigd.exe 12->25         started        27 schtasks.exe 12->27         started        signatures6 process7 dnsIp8 62 paygateme.net 146.70.57.34, 2286, 49704, 49706 TENET-1ZA United Kingdom 14->62 64 geoplugin.net 178.237.33.50, 49708, 80 ATOM86-ASATOM86NL Netherlands 14->64 50 C:\Users\user\...\time_20250514_194305.dat, data 14->50 dropped 52 C:\Users\user\...\time_20250514_190720.dat, data 14->52 dropped 54 C:\Users\user\...\time_20250514_183203.dat, data 14->54 dropped 56 498 other malicious files 14->56 dropped 66 Detected Remcos RAT 14->66 68 Maps a DLL or memory area into another process 14->68 70 Installs a global keyboard hook 14->70 29 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 14->29         started        32 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 14->32         started        34 SecuriteInfo.com.Win32.PWSX-gen.22684.1131.exe 14->34         started        44 2 other processes 14->44 36 WmiPrvSE.exe 19->36         started        38 conhost.exe 19->38         started        40 conhost.exe 21->40         started        42 conhost.exe 27->42         started        file9 signatures10 process11 signatures12 96 Tries to steal Instant Messenger accounts or passwords 29->96 98 Tries to steal Mail credentials (via file / registry access) 29->98 100 Tries to harvest and steal browser information (history, passwords, etc) 32->100
Threat name:
Win32.Backdoor.Remcos
Status:
Malicious
First seen:
2024-04-05 10:48:48 UTC
File Type:
PE (.Net Exe)
Extracted files:
10
AV detection:
24 of 35 (68.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection rat spyware stealer
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Checks computer location settings
Reads user/profile data of web browsers
NirSoft MailPassView
NirSoft WebBrowserPassView
Nirsoft
Remcos
Malware Config
C2 Extraction:
paygateme.net:2286
Unpacked files
SH256 hash:
71dab87ac5b7b80468ef8ccb16b74b39cc862b7fb9a6e430e4cd7e375dbe6c27
MD5 hash:
df9e546ebe70f8307bc8e6ad3aa08f0f
SHA1 hash:
d649fef8643e0a0c870519420522d5ca23dd7382
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
498b4a265a27f8362fea4fcf15a184b220475c891249c892406030eb3b245c00
79e473fb7f021d7b394ac013c2abcca1a094a918b6f2edb48c0ed18d7b3b7460
53ffe79bd4c176d257a5b0a5a147ecaa522356d3ea80ab83dc6f8c55bd545c08
2d4255b15429696714b3c6e55077d3d95cfbc71a746406385cc4ba5025eb6a45
da6f3f1f642c13d2b7bf4c86e2686c5e1b606dbe0838423998c15742940545e9
a48b8a6ca726f32569a7e2041803898a902437ee7724da53accfb6dc52fa8a87
c94be0d3693316359c2e48e43baf51dff4f0b8d5efab6050962a09ef46ead4dc
24798002b81be4c9b37539e1abea61cccb014cbd427fe1a27d6822e1ffedc7d9
9fc2770fbd67c9b6f9f244ac6ac0fa8810c3d50e08c7d77b332bf1447ab77fab
2c8008052d15b5a7a61808357f2085226f7f9bc9619bb2040c27024a6423b9d2
1ba9c4dfbdfb55f6588c8887006f2851716eb6e53eb2bd1bccd591aa9e182da7
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
38f97adf003d63f84a6c5bc35c9d9096901e7292e763bd9fbeabdafa1aa5fa78
12f1562e82415f8f320bc830dc6047870ea78ceb7e827af394dbe428d8ebc930
450160aa7afe149bc82992b2dd8f44fdaf64fcaec24d7b9c8522251f538a7636
859876f4be1e8206802a3468eb52a143bf5bc15724c0b66b70d98edd79c06a08
f48dfafeefb4b36315d6b8f987df1026d29c102bd24703a08cc4d4d41a483505
5408e8b840c407984e92034c26e937b1785c5f4b6762b14f2f7a31cec4d982d8
74a07ee3f0060987ebcb09e588ac1299a9d2a19e2f4139385f7880c229e2c8cf
da1903e676a7609f931a23ef7a653af4c1be9ef5242a80bdca67cb076d372bfd
cf432fc47407df80dcf984cf5d8d1a6aaed7c8c2a4c9b3a76627b4194bb9c782
73c44dbb7ece4e2fee17409d2d0ebcc82a77dd86c7ab0c9da9d8453cab59fbcc
c161b936b669673a3441c19755270abebe800846e8a01be9477e634d91b44635
191239a61c70ba900694d294a164f4a162b84d11672871fbb5389967bbf52c7e
ff2ae4fd71daa1a98edd5f88b743a5daa5fb29f70b87dee08fec25313a3640f1
554b40336bad24df88cbde544cdf20d553d02ce7fee5dab9a82318d7c21471e0
bc5f1294caaee05297ad1547f2f6ec4a309c16f7caf906f21038269d72f54957
15df84ca3a0c112b7ab461d6ee7603fcec8e24da91d4042d3ab018f87530b6ac
32aeea1990475960922b9a0bbda5a7edc864a3c70e4b8c5e84b16e269ea6fc7c
677f5939951053c165cdff92b6fa68d53748365869a978b77c2a501a46d1c4c8
67a792fced715c64610c55d8c01b16d66080c10004ed572e664c324468afdd7d
02a5ec5d9037cdd26b3f1ade8ea4028fbd0947284bfb3d7649e065d22db0ef91
704427aa451d261a1a92a6e834a1ee2be50971a012e711f9f660403904a9622c
6fd8e845cfa1bf8f809f0f372c2d4e955c6a3b6c0e88fb8f474a2645f587ecf0
9f6eb9b6b3bf92a75e32208dd51ce6307fa5ccdae27f02f0c7e2712544c2c04f
8506e0fdcf9ce49bd939a62bacd3e4d1af3522d72e660382684b1e4d1bb8e6b7
8fb359ccf3a3b6a0eff8204f9ee27c2dc41b3270721716192a7ef9253453b59b
8f53280f0b7807f08cf03152768d385200db1ad864b256fd9e7decbc846b05a2
70517116e2400906af6125849ac27b66159a45f6f1782178351e82bfe5ba205c
1711d935991cb37bd208dec08aefb47cf049baa4aa465d3188feccd8d330e72d
b1a574a7a0aad03e9f0a8470fd53013c565e67461ff21fc79e1bb6205974adb1
190504e991bb8bb608cf87db9ee7c7549999a17970251490ce85282f85cb49aa
f4eaa74eb268a58cff6f5d37607758bd49cc00af060da799857ae10cfd59efb2
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
2a0a27371b6f4d355c3264fcc668d8a0fe1af7ebb8b19dca3b5cdf20a3282d65
f486a970c3228b346008eb169500d373560ea047084818b77357ba68bfa960af
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
bd7f924e17174165e42ee077f973be26f07c6653ff33951ff9c53fb7cc833bae
1dea51f5680fedc83402ccb9401ae907c9493ef8625a76fe6f6cd9f475021e6a
a433dfdb99b293b73898ac05be0fbf6baa9d79976655b0c51ba5a5a0066a2632
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
da86da7fc086aa8262222feed9f4cd4df4c4538e77d90a7c160b1c794f298b92
ef8ad9042176ddf7dae5199f0135c2efabf224a45ac52f0ebc054b7ee9806c04
efb67364fa543ceddc607094c10c4b71f3baac1f45de5c2c759c489f97a64ec2
47cf473f0a0c146e5ae4a37b987c297be41d82af40d53e4dc750ca9b66fa7ea6
9d1f9f7012962df24baa3c3ac0816333abecf2a433953f68dab7e7673fac59aa
4b4c3585bbf95af33fac18ae92347069e2b732626cc6c7984ebfef92ea0a89b0
31fea186e7379793d1d9b37d2a981ed0fb05d40ee7d62e227eac695106ebbe2f
d23bd1fbaae83547ec6aba06ad8b4eef5119bd4a0f66634a6726b6ccd5dc3c78
dd14afafbf11a0251a0c5c56b3ef8b0be205cd4ed5d70fe77df7fdc90a039a4a
36ea8608df9b009caf566d4309832531c532d9eaf5c28b5b1657acf54c471209
95e4dd6cc5a341f4440a113e0a832175aa2f5baafd9c7483255a18088e1c2764
44ba13a119d19891a586d95310d8a51e9440fe2c1659b397d5795ecab37e3eeb
SH256 hash:
7b976f1f386cecc61f1befa01871d76248c16612735e9a444782d50c99b8b2d7
MD5 hash:
d3c7d01cf1bcd78089d66ba44dca0c5f
SHA1 hash:
5e8a1b103c940fe49912aa2eed5da1c9c22abc1b
Detections:
INDICATOR_EXE_Packed_SmartAssembly
SH256 hash:
6790b2726b9ebff817c7aebef6b318e6bcce4f602bf491f9af75de1e5ba75ea8
MD5 hash:
e99d6e93e76158125c8c2e10c81950c2
SHA1 hash:
1765aa62fec074a26bcb32d8ea352bfd9778a4b0
SH256 hash:
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
MD5 hash:
636a54861ddd167065f294cc76fca7ba
SHA1 hash:
7e3eba28bc4b89801c91de5450aa28da5c6ff941
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AgentTesla_DIFF_Common_Strings_01
Author:schmidtsz
Description:Identify partial Agent Tesla strings
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:iexplorer_remcos
Author:iam-py-test
Description:Detect iexplorer being taken over by Remcos
Rule name:INDICATOR_EXE_Packed_MPress
Author:ditekSHen
Description:Detects executables built or packed with MPress PE compressor
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Confidential_Data_Store
Author:ditekSHen
Description:Detects executables referencing many confidential data stores found in browsers, mail clients, cryptocurreny wallets, etc. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_References_Messaging_Clients
Author:ditekSHen
Description:Detects executables referencing many email and collaboration clients. Observed in information stealers
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:maldoc_getEIP_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:meth_get_eip
Author:Willi Ballenthin
Rule name:meth_stackstrings
Author:Willi Ballenthin
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:QbotStuff
Author:anonymous
Rule name:Remcos
Author:kevoreilly
Description:Remcos Payload
Rule name:REMCOS_RAT_variants
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:TeslaCryptPackedMalware
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Remcos_b296e965
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.
Rule name:win_remcos_w0
Author:Matthew @ Embee_Research
Description:Detects strings present in remcos rat Samples.
Rule name:yarahub_win_remcos_rat_unpacked_aug_2023
Author:Matthew @ Embee_Research
Rule name:yara_template

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

Executable exe 8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c

(this sample)

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments