MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a01d4a1b86c5cef8726cc8f8c26a93739f10d1f68d101f9d2d94302dc248704e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a01d4a1b86c5cef8726cc8f8c26a93739f10d1f68d101f9d2d94302dc248704e
SHA3-384 hash: c96d464ba2a966cae01e3b18d913a0c59c06581ffe24f055cadd299de472f0fb508fa25f0c87e4e1d4844e57fc2c5c63
SHA1 hash: 6f1013c787be7acce86d8669573c19721d9e26a0
MD5 hash: 94e3a6b9b234d6adcc789670e485026e
humanhash: network-iowa-quiet-bacon
File name:PO# 1740697, 1740696 , 1740698 500pcs.exe
Download: download sample
Signature RemcosRAT
File size:520'192 bytes
First seen:2020-04-30 07:34:20 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 529bd53dfc9bd129978e470f6941389c (1 x RemcosRAT)
ssdeep 6144:/7bcSob0CSYgR4FzGDwmoRd3gGnT/jmVwqHcyp5bk:k0CSZR4Is33X/CVRcyrbk
Threatray 1'320 similar samples on MalwareBazaar
TLSH 5DB4E84A38E2CF29ED9977725D2C2CD3EA9C52F4DB390D49EF0665CEABEBE441115002
Reporter jarumlus
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::EVENT_SINK_AddRef

Comments