🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ff9678230d65b2e02f5c4117049499bd7b7ade84860884dccf49df2f2465dff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemoteManipulator


Vendor detections: 13


Intelligence 13 IOCs YARA 6 File information Comments

SHA256 hash: 8ff9678230d65b2e02f5c4117049499bd7b7ade84860884dccf49df2f2465dff
SHA3-384 hash: ad4aa9d8a7e2d3af426d9a820cdd2d8656227453baefcfefbe4318f95cc107042f74e59b045371631323c249cc1a3d95
SHA1 hash: 6b8516e2c02776203a8076fdbf76c06af4d4c062
MD5 hash: 1d90da0dee83515bf06756b287666070
humanhash: ack-sixteen-six-failed
File name:SecuriteInfo.com.PUA.Tool.RemoteControl.18.2563.12284
Download: download sample
Signature RemoteManipulator
File size:16'983'536 bytes
First seen:2024-04-28 09:31:54 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 38be718d163809a15e0c7a672311fe41 (18 x RemoteManipulator)
ssdeep 393216:8BPoGOaERPtW2BAbKrocC+GRYlqZKdcPew3bDerMdRYs:8BAGrqWqocWeqZjei/d
TLSH T16B073356F7F14429E8FA8ABA4DBE0B14175BBCD81A0393CD1398F12C9CB63415DA439B
TrID 71.9% (.EXE) UPX compressed Win32 Executable (27066/9/6)
11.9% (.EXE) Win32 Executable (generic) (4504/4/1)
5.3% (.EXE) OS/2 Executable (generic) (2029/13)
5.3% (.EXE) Generic Win/DOS Executable (2002/3)
5.3% (.EXE) DOS Executable Generic (2000/1)
File icon (PE):PE icon
dhash icon c4dacabacac0c244 (61 x RemoteManipulator)
Reporter SecuriteInfoCom
Tags:exe RemoteManipulator signed

Code Signing Certificate

Organisation:Ter-Osipov Aleksei Vladimirovich
Issuer:DigiCert SHA2 Assured ID Code Signing CA
Algorithm:sha256WithRSAEncryption
Valid from:2021-05-25T00:00:00Z
Valid to:2023-07-18T23:59:59Z
Serial number: 0e62fe155fb23337f1cffbc7bf03b6d1
Intelligence: 6 malware samples on MalwareBazaar are signed with this code signing certificate
Thumbprint Algorithm:SHA256
Thumbprint: 400b879e19ee2e650226a3275e2fae3e9629c6508400a7916e381bc936b275dd
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
1
# of downloads :
323
Origin country :
FR FR
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
8ff9678230d65b2e02f5c4117049499bd7b7ade84860884dccf49df2f2465dff.exe
Verdict:
Malicious activity
Analysis date:
2024-04-28 09:55:08 UTC
Tags:
rat rms

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Launching a service
Connection attempt
Sending a custom TCP request
Creating a file in the Windows subdirectories
Verdict:
Malicious
Threat level:
  10/10
Confidence:
89%
Tags:
fingerprint hook keylogger lolbin overlay packed packed rat remote remoteadmin shell32 unsafe
Malware family:
Remote Utilities LLC
Verdict:
Suspicious
Result
Threat name:
RMSRemoteAdmin
Detection:
suspicious
Classification:
evad
Score:
36 / 100
Signature
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Query firmware table information (likely to detect VMs)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1432852 Sample: SecuriteInfo.com.PUA.Tool.R... Startdate: 28/04/2024 Architecture: WINDOWS Score: 36 54 Malicious sample detected (through community Yara rule) 2->54 56 Multi AV Scanner detection for dropped file 2->56 58 Multi AV Scanner detection for submitted file 2->58 9 SecuriteInfo.com.PUA.Tool.RemoteControl.18.2563.12284.exe 18 2->9         started        13 chrome.exe 1 2->13         started        process3 dnsIp4 32 C:\Users\user\...\webmvorbisencoder.dll, PE32 9->32 dropped 34 C:\Users\user\...\webmvorbisdecoder.dll, PE32 9->34 dropped 36 C:\Users\user\AppData\Roaming\...\webmmux.dll, PE32 9->36 dropped 38 7 other files (5 malicious) 9->38 dropped 64 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 9->64 16 rfusclient.exe 3 9->16         started        46 192.168.2.4, 138, 443, 49672 unknown unknown 13->46 48 192.168.2.7 unknown unknown 13->48 50 239.255.255.250 unknown Reserved 13->50 19 chrome.exe 13->19         started        file5 signatures6 process7 dnsIp8 52 Query firmware table information (likely to detect VMs) 16->52 22 rutserv.exe 2 16->22         started        40 www.google.com 172.253.122.104, 443, 49738, 49754 GOOGLEUS United States 19->40 42 google.com 19->42 signatures9 process10 signatures11 60 Query firmware table information (likely to detect VMs) 22->60 62 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 22->62 25 rutserv.exe 7 14 22->25         started        process12 dnsIp13 44 46.29.8.146, 49747, 49755, 49756 TELEMAKSRU Russian Federation 25->44 66 Query firmware table information (likely to detect VMs) 25->66 29 rfusclient.exe 2 25->29         started        signatures14 process15 signatures16 68 Query firmware table information (likely to detect VMs) 29->68
Verdict:
malicious
Result
Malware family:
Score:
  10/10
Tags:
family:rms rat trojan upx
Behaviour
Modifies data under HKEY_USERS
Modifies system certificate store
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Executes dropped EXE
Loads dropped DLL
Checks computer location settings
UPX packed file
RMS
Unpacked files
SH256 hash:
dfce76b3f2a24fcf78b0e5a5836ab2a0a89b20d0a2dc59a6d22b6ae1353c6476
MD5 hash:
6e3d18a8397d92f5bc3374eb546fa0db
SHA1 hash:
b9ddadfe119005d6bfb90ee03aa3c5ac6e401166
SH256 hash:
f27bd2379f5e9fcdf9c0cca98a43024bf6d04b3265f60c410fc67d936fa5b0f3
MD5 hash:
ed87ff9485fac3489daf1d31f33a16aa
SHA1 hash:
50aee59c83869f350c6ca57524d8da283a34455a
SH256 hash:
2429a45027d9c73ff72a37702869a75b2e14af219b8c11d6856c65258bc9773a
MD5 hash:
83c95b08ad391183cb5edb6ed1c492d0
SHA1 hash:
2cadc38137b534f320bb1d2893ca0d6acb92a99d
SH256 hash:
ec2e2574a6b6443ad1f51e533d2f2bb429890c9cf03baad670f046c0f1e5305a
MD5 hash:
271e9be627042f677a8e02b73694a16d
SHA1 hash:
e5be0c3229fd661b7bada93c684bb25efeecad3b
SH256 hash:
740329d3cd129db383e9c85fe9811de4e65aa1275bc712c2a577c0ca4a31c531
MD5 hash:
a3e8a3300819c762c1db24d136ed0b25
SHA1 hash:
4d43c4dc9ebefcf4b68a87ee6706c12890ef790a
SH256 hash:
a033adc24743cd453607860efcff0922a09abaf1db7dfa903e81fd0c7c94db01
MD5 hash:
0d561f1ac469febf4bcd51d24a44d7ac
SHA1 hash:
f20f7bbd55f01bbd36189851824d337cf0c371f2
Detections:
win_rms_auto win_rms_a0 MALWARE_Win_RemoteUtilitiesRAT
SH256 hash:
1c374c7a2882a82afc1697fbac5f6fef2bd36d6af3114c53fb16a54a2457e9c2
MD5 hash:
5999b747337c9fbeb449484d11e65b67
SHA1 hash:
10ed7f436500bcc890171941a6ba6095fd4568ba
Detections:
win_rms_a0 MALWARE_Win_RemoteUtilitiesRAT
SH256 hash:
8ff9678230d65b2e02f5c4117049499bd7b7ade84860884dccf49df2f2465dff
MD5 hash:
1d90da0dee83515bf06756b287666070
SHA1 hash:
6b8516e2c02776203a8076fdbf76c06af4d4c062
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:PE_Potentially_Signed_Digital_Certificate
Author:albertzsigovits
Rule name:UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser
Author:malware-lu
Rule name:UPXv20MarkusLaszloReiser
Author:malware-lu

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
MULTIMEDIA_APICan Play Multimediawinmm.dll::timeGetTime
SHELL_APIManipulates System Shellshell32.dll::ShellExecuteW
WIN_BASE_APIUses Win Base APIKERNEL32.DLL::LoadLibraryA
WIN_REG_APICan Manipulate Windows Registryadvapi32.dll::RegLoadKeyW

Comments