MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a29068c2164d609c5dcb0cca032b10ec0573159f7b83dad43a278811bc6cb8c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: a29068c2164d609c5dcb0cca032b10ec0573159f7b83dad43a278811bc6cb8c9
SHA3-384 hash: fa011b997f8b0d502bc8603b353648f06668f6d0c133eb539248618389d69cbe26a508d2888a089f528dd2638925805f
SHA1 hash: 48ba536523f1c9b539686a08299df60c50397847
MD5 hash: c7e70bf74749e7d12af58ba952fe15e5
humanhash: enemy-mars-artist-charlie
File name:Totalitar.exe
Download: download sample
Signature RemcosRAT
File size:102'400 bytes
First seen:2020-04-13 17:13:10 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 4fc91aeac9c761c908cf99cac94db12c (1 x RemcosRAT)
ssdeep 768:D3nWYXBGeyggiocamR/OHrXnxLhC2dVoLp9I4aKSW/DUQ+XknHA6:LnW8HFuXmJOHDDCEy9IgZ/qkg6
Threatray 1'122 similar samples on MalwareBazaar
TLSH 1FA3E6523A88FEA5D01549B29EB5C2FC5178BD309C86259738C53F0F3AB48A37856F87
Reporter c_APT_ure
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Fareit
Status:
Malicious
First seen:
2020-04-10 04:38:51 UTC
File Type:
PE (Exe)
Extracted files:
6
AV detection:
25 of 31 (80.65%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
VB_APILegacy Visual Basic API usedMSVBVM60.DLL::__vbaObjSetAddref
MSVBVM60.DLL::EVENT_SINK_AddRef

Comments