MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a144d424d0ace63551d67ee67efe8ff6242df2b5c55d8f2494e0731f2d88f711. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 7
| SHA256 hash: | a144d424d0ace63551d67ee67efe8ff6242df2b5c55d8f2494e0731f2d88f711 |
|---|---|
| SHA3-384 hash: | 8b79ad47bcacf035515d19162c5fc8f6657d9de12bcd5e7ada35b17127eb8ff6902c7f50622ebeb3d2bd34cac995e24f |
| SHA1 hash: | 4458290c583ef314bda1605310f05222ad36571e |
| MD5 hash: | 157c92eee83ac9bcde53da36880c886f |
| humanhash: | robert-undress-louisiana-hawaii |
| File name: | Atikmdag Patcher 1.4.8.sfx.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 2'588'365 bytes |
| First seen: | 2021-01-19 00:17:09 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | fcf1390e9ce472c7270447fc5c61a0c1 (863 x DCRat, 118 x NanoCore, 94 x njrat) |
| ssdeep | 49152:qcm6yAg0RWQGeiyjGvLcUPZpRyLxC3pGVZP+gZjP2JJZjW/vUSO:qV6y70RWSOLRELxC5+ZP+aMS/v+ |
| Threatray | 1'717 similar samples on MalwareBazaar |
| TLSH | 1EC52312F9C294B2C437563D2529AA25397EBC300F24CB9B63E86E7DAD304D17634B67 |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
# of uploads :
1
# of downloads :
196
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
Atikmdag Patcher 1.4.8.sfx.exe
Verdict:
Suspicious activity
Analysis date:
2021-01-19 00:19:52 UTC
Tags:
n/a
Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Detection:
n/a
Result
Verdict:
Malware
Maliciousness:
Behaviour
Creating a window
Searching for the window
Creating a file in the %temp% subdirectories
Creating a process from a recently created file
Deleting a recently created file
Creating a file in the Program Files subdirectories
Moving a file to the Program Files subdirectory
Creating a file
Sending a custom TCP request
Sending a UDP request
Launching a process
Transferring files using the Background Intelligent Transfer Service (BITS)
DNS request
Enabling the 'hidden' option for files in the %temp% directory
Moving a recently created file
Launching cmd.exe command interpreter
Unauthorized injection to a system process
Result
Threat name:
Remcos
Detection:
malicious
Classification:
troj.spyw.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Contains functionality to capture and log keystrokes
Contains functionality to inject code into remote processes
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Detected Remcos RAT
Drops executable to a common third party application directory
Hijacks the control flow in another process
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Uses nslookup.exe to query domains
Writes to foreign memory regions
Yara detected Remcos RAT
Behaviour
Behavior Graph:
Detection:
remcos
Verdict:
malicious
Label(s):
remcos
Similar samples:
+ 1'707 additional samples on MalwareBazaar
Result
Malware family:
n/a
Score:
8/10
Tags:
n/a
Behaviour
Suspicious behavior: MapViewOfSection
Suspicious use of FindShellTrayWindow
Suspicious use of SetWindowsHookEx
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of WriteProcessMemory
Drops file in Windows directory
Drops file in Program Files directory
Loads dropped DLL
Executes dropped EXE
Blocklisted process makes network request
Unpacked files
SH256 hash:
c7fbdc61eb62c05e40295617e2db75877672931f751a770d2629e6eab6075f2c
MD5 hash:
abf6c724b20844d5b0073988a58faf1e
SHA1 hash:
7a8269d5b2ae623f8148ce9863f48f7e12ce036b
SH256 hash:
f19ab4e6d62238045775169832428f18e055fc245ddc09cd9c9296ea9766b47f
MD5 hash:
e3453d759b4fcc0e0b06912513892a40
SHA1 hash:
8086397401f8721a5a9813af6abb8272750a26df
SH256 hash:
476ee34ee6778452d4a66295a6d5f425dff80130c3cd71c62225f9ed3f4b332b
MD5 hash:
b50f36ec53cdc8ec24cb7f4224de8d19
SHA1 hash:
6bcd00f674b0c0328fafc5c8c93b6625454bce20
SH256 hash:
645e8be8fe519d598a34a8958d0e6f20ad0e7cdd4d395b872330d5d9cd5a1027
MD5 hash:
47a77b4f8c7451811545e0be34c7cc88
SHA1 hash:
8f6a09370f4ecb57b5bb39ffe57dd72bca7bcc05
SH256 hash:
a144d424d0ace63551d67ee67efe8ff6242df2b5c55d8f2494e0731f2d88f711
MD5 hash:
157c92eee83ac9bcde53da36880c886f
SHA1 hash:
4458290c583ef314bda1605310f05222ad36571e
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Delivery method
Distributed via web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.