🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98d674391fcd95ecc27589899bed22a2f9cff38c0fea0eba9265ad1e178645af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 98d674391fcd95ecc27589899bed22a2f9cff38c0fea0eba9265ad1e178645af
SHA3-384 hash: 98616d784ce77243ac9bc70a2dd38c5a1ebf1b177a05c36e1c374f8952ce5e15f0e683ca62bdc2bbd0aba500c904b02e
SHA1 hash: 941d1cb3ee327314e74d05e88572112ad5258fa9
MD5 hash: 572b47b90ba43731ff0bb611a272a8ea
humanhash: oscar-failed-blue-enemy
File name:hesaphareketi-01.PDF.r00
Download: download sample
Signature RemcosRAT
File size:867'986 bytes
First seen:2023-04-04 08:45:24 UTC
Last seen:Never
File type: r00
MIME type:application/x-rar
ssdeep 24576:HSzXygV6qylh0GovXefgPRh+F6p+bYZ/6lXKPz:Spsq6ePRhpeOwXKPz
TLSH T15B05230FE63DC8CD013EEBA44FC92BE59CDCD992911DDD66690AC19F62558B8F80603B
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Reporter FBussoletti
Tags:geo r00 RAT remcos RemcosRAT TUR


Avatar
FBussoletti

Sayın

Şubemiz nezdindeki 6200158 numaralı (IBAN: TR43 0006 2000 3550 0006 2001 58) TL hesabınızın, 01.03.2023 ile 04.04.2023 tarihleri arasındaki hareketleri ile 04.04.2023, saat 10:20 itibariyle bakiyesi ekte yer almaktadır.

Saygılarımızla,

Türkiye Garanti Bankası A.Ş.
ATATÜRK O.S./ÇİĞLİ Şubesi

Intelligence


File Origin
# of uploads :
1
# of downloads :
122
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:hesaphareketi-01.PDF.exe
File size:906'240 bytes
SHA256 hash: 11327f3b5123a0f6325b9370d4321bddc00ef1619f6da209503ae1370b24121e
MD5 hash: 291a8d6fe1adf2fca024566c8503d764
MIME type:application/x-dosexec
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
packed
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-04-04 08:46:09 UTC
File Type:
Binary (Archive)
Extracted files:
10
AV detection:
9 of 37 (24.32%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:pe_imphash
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:Suspicious_Macro_Presence
Author:Mehmet Ali Kerimoglu (CYB3RMX)
Description:This rule detects common malicious/suspicious implementations.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

r00 98d674391fcd95ecc27589899bed22a2f9cff38c0fea0eba9265ad1e178645af

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments