MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a0a124777df35d015c84f61af9a8e4d0dba82120a30fa031b73b885a13d88214. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 16
| SHA256 hash: | a0a124777df35d015c84f61af9a8e4d0dba82120a30fa031b73b885a13d88214 |
|---|---|
| SHA3-384 hash: | 392aad19677b0479dae24a1d9bafd5f062933e48f8dfb58b97bbf3df556292bef7a6306eafd620627567ad41e2b3680d |
| SHA1 hash: | e2ba4eb05fd656a31f0fd11a97cce10e63c84303 |
| MD5 hash: | 96235061dd61deed3d950271b9e9e548 |
| humanhash: | magnesium-fruit-freddie-alaska |
| File name: | Products And Material.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'031'680 bytes |
| First seen: | 2022-11-30 14:17:06 UTC |
| Last seen: | 2022-11-30 15:44:15 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 24576:9XGfZN6eIwuBvT12KJ/5DN0wgCz27D5U1/vL:S6jw02wxh0wgXD5 |
| Threatray | 2'291 similar samples on MalwareBazaar |
| TLSH | T1D1259D9573B28473F58F0139815531CC2E7DA943AAE5F2076B763A8546027BFFA9CE02 |
| TrID | 60.4% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.8% (.SCR) Windows screen saver (13097/50/3) 8.7% (.EXE) Win64 Executable (generic) (10523/12/4) 5.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.1% (.EXE) Win16 NE executable (generic) (5038/12/1) |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
a0a124777df35d015c84f61af9a8e4d0dba82120a30fa031b73b885a13d88214
c0499439a0e94bca738d814f9626f30639c96a7664a19e77c3eafda15ddc6ef7
36a2cbe976c9c3fb77f83c521dc34752c4996f45d65c77372949fc62eb21f838
86e3a5e24146d1a42311819bc13c20ca51ca84849dac11f660e4f366a93c36cd
01304c92721e17fea51265cdb72ac92ddfadd72cdf2a69b6316d2fcea6142472
519cdc27424d8eb3cac48f7e148ce68123980a03a8692c1139f229fec66a5615
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.