MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 9474ca0fa771bd4dd2202e312ada0090f6890635b9039b5be855cc7cb8eab6ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 15
| SHA256 hash: | 9474ca0fa771bd4dd2202e312ada0090f6890635b9039b5be855cc7cb8eab6ee |
|---|---|
| SHA3-384 hash: | a4dbb5e47fca939747faa104f9b609b6a15a61dfc4185d94e19fc9166795fd359ef4f3f9e579e34aed17cca242955b2d |
| SHA1 hash: | 03c258ec0919d352f501cacc245309ed5ccb7c0f |
| MD5 hash: | 34b5b4031e59623e75d7de6e1c9935ff |
| humanhash: | alaska-mississippi-early-april |
| File name: | rIMAGEDDOC0559D.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 929'792 bytes |
| First seen: | 2023-07-04 12:04:38 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 8744464f2d808f7b51fec10c17042328 (3 x ModiLoader, 2 x AveMariaRAT, 2 x RemcosRAT) |
| ssdeep | 24576:xgLzNa28Rcr2O86+6MDUlnEXYfWGOvD7QKM:xgL4HA2/KrJ |
| Threatray | 2'742 similar samples on MalwareBazaar |
| TLSH | T16115B037E2B14877D17619B84F0A53E45C2C7E271A38A84ABFE87D89DF3A2417439193 |
| TrID | 38.7% (.EXE) UPX compressed Win32 Executable (27066/9/6) 18.7% (.SCR) Windows screen saver (13097/50/3) 15.0% (.EXE) Win64 Executable (generic) (10523/12/4) 9.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 6.4% (.EXE) Win32 Executable (generic) (4505/5/1) |
| File icon (PE): | |
| dhash icon | 74ecc4e2e484909c (3 x ModiLoader, 3 x RemcosRAT, 2 x AveMariaRAT) |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
BRVendor Threat Intelligence
Result
Behaviour
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
96bde9151480b20318275c2c0e045dc13486a76cf81465e4e02ad97cf37140b0
6a7be0b8db3655e564255f25f80cdda361dcb00b477622db0bab226502860433
99cd4e51fb0f2d9ba76ee4d12afd5c3cd096f0c390ecf657ea3a3d78158451ef
8f82951ca10a326a39d6f1a4e91515dbac43b7c0f8c29b920de3522e6a870892
9474ca0fa771bd4dd2202e312ada0090f6890635b9039b5be855cc7cb8eab6ee
5edb99afba36f3aa19c0b065b263b65e27d37d588c5441d5f9518e8423480344
7c397e8792e6dbc64b6d5fd80a2ed4d82e76c1e0e9d7a262f089e1c1e8c438df
26970093951834c49005224a8e46bbc2a52a9ed4a9e8ae376a6d97d2817ab671
85383a8f1761aba192877153fbca884993d7b54e2673481a1bb78648f58f236e
cd26009a2cfa0a5f8b8e44786b045b4a0d8faf78ae5ae044a64226f3ced2bda7
912dcabc2feb02fa2ba9794b2b6f3274281e2821aa9cfed73c94e99a30f7d1ea
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | BitcoinAddress |
|---|---|
| Author: | Didier Stevens (@DidierStevens) |
| Description: | Contains a valid Bitcoin address |
| Rule name: | CMD_Ping_Localhost |
|---|
| Rule name: | Disable_Defender |
|---|---|
| Author: | iam-py-test |
| Description: | Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen |
| Rule name: | meth_get_eip |
|---|---|
| Author: | Willi Ballenthin |
| Rule name: | shellcode |
|---|---|
| Author: | nex |
| Description: | Matched shellcode byte patterns |
| Rule name: | Typical_Malware_String_Transforms |
|---|---|
| Author: | Florian Roth (Nextron Systems) |
| Description: | Detects typical strings in a reversed or otherwise modified form |
| Reference: | Internal Research |
| Rule name: | Typical_Malware_String_Transforms_RID3473 |
|---|---|
| Author: | Florian Roth |
| Description: | Detects typical strings in a reversed or otherwise modified form |
| Reference: | Internal Research |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.