MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f0ce7232480a5ed7ef09cae8d6b61350835649ed50080b0b6c814bc15e12481. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 8f0ce7232480a5ed7ef09cae8d6b61350835649ed50080b0b6c814bc15e12481
SHA3-384 hash: 5e1627f298a80d5e93b680383b70c965b4ef4e351655ea4dfc5023f08c8a6e61368997125a45867452cd7c288d53a464
SHA1 hash: 7cf82d0a1afea8bab10d53071c47592b18e4b46a
MD5 hash: ad66bb2d2a6676bc4d1c2ba725911e4d
humanhash: papa-autumn-carpet-may
File name:DHL_636636.exe
Download: download sample
Signature RemcosRAT
File size:1'325'570 bytes
First seen:2020-05-08 20:11:27 UTC
Last seen:2020-05-08 20:58:58 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 78243cbfbc4dd1522113701bde066d1e (4 x AveMariaRAT, 3 x RemcosRAT)
ssdeep 12288:5fXeibdNUawAHXqJyjUcgAxKRouPCuinlyudxglGXgbId7NESgK1fF8hS:5vKaw86SHfKVPAKlAgsd7NNLF/
Threatray 1'058 similar samples on MalwareBazaar
TLSH A9551876A381C8FDD3615634CC2B39B394BA7B30255A7049BEE0DD2D5A39A90B11D38F
Reporter James_inthe_box
Tags:exe RemcosRAT

Intelligence


File Origin
# of uploads :
2
# of downloads :
88
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Injector
Status:
Malicious
First seen:
2020-05-08 20:10:46 UTC
File Type:
PE (Exe)
Extracted files:
96
AV detection:
25 of 31 (80.65%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Legitimate hosting services abused for malware hosting/C2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments