🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab27dd46ddc5d8e0bf47b618f537a633ba5176f9a3d9f647de7cf3b2e7e7567c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: ab27dd46ddc5d8e0bf47b618f537a633ba5176f9a3d9f647de7cf3b2e7e7567c
SHA3-384 hash: cced414631860697e318a43cbab09aa9c5121dedbe4a7da16309a1f772e7b1e0f3a296279709d5fa082c6825bb3ca501
SHA1 hash: 5a526b791cee9502ad39a2f0009b289161a3d97a
MD5 hash: 8c5a092d99f1bec3efe489552db1b2b8
humanhash: earth-alabama-pip-sixteen
File name:DocumentsDOC03029314B76858448A444B4C03EEC7E6F.bat
Download: download sample
Signature RemcosRAT
File size:2'701'509 bytes
First seen:2024-02-06 14:55:17 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 24576:4pMnYCoTzMBGtRfB7M0iCIvTNzaNC5+PSCgcCPdQtJdaTrtFsAzDmThQNWmeC8qN:4p0YTTz5RRm6UCmWSUIuXhY4wV
TLSH T1B0C502378DB988D5A3B551BD95AD6FCB0FF8588B80144BB68BC8F29A05E9D705F2D00C
TrID 45.4% (.MP3) MP3 audio (ID3 v1.x tag) (2500/1/1)
36.3% (.TXT) Text - UTF-16 (LE) encoded (2000/1)
18.1% (.MP3) MP3 audio (1000/1)
Reporter abuse_ch
Tags:bat RAT RemcosRAT


Avatar
abuse_ch
RemcosRAT C2:
103.186.117.186:2404

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
NL NL
Vendor Threat Intelligence
Verdict:
No Threat
Threat level:
  2.5/10
Confidence:
100%
Tags:
masquerade obfuscated
Result
Threat name:
Remcos, DBatLoader
Detection:
malicious
Classification:
rans.troj.spyw.expl.evad
Score:
100 / 100
Signature
Allocates many large memory junks
Allocates memory in foreign processes
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Drops PE files to the user root directory
Drops PE files with a suspicious file extension
Early bird code injection technique detected
Found large BAT file
Found malware configuration
Installs a global keyboard hook
Machine Learning detection for dropped file
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Queues an APC in another process (thread injection)
Sample is not signed and drops a device driver
Sample uses process hollowing technique
Sigma detected: Execution from Suspicious Folder
Sigma detected: New RUN Key Pointing to Suspicious Folder
Sigma detected: Parent in Public Folder Suspicious Process
Sigma detected: Remcos
Sigma detected: Suspicious Creation with Colorcpl
Sigma detected: Suspicious Program Location with Network Connections
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Snort IDS alert for network traffic
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Yara detected DBatLoader
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1387647 Sample: DocumentsDOC03029314B768584... Startdate: 06/02/2024 Architecture: WINDOWS Score: 100 73 www.tarmacagraga.com 2->73 75 dual-spov-0006.spov-msedge.net 2->75 77 6 other IPs or domains 2->77 89 Snort IDS alert for network traffic 2->89 91 Found malware configuration 2->91 93 Malicious sample detected (through community Yara rule) 2->93 95 15 other signatures 2->95 11 cmd.exe 1 2->11         started        signatures3 process4 signatures5 121 Uses ping.exe to sleep 11->121 123 Uses ping.exe to check the status of other devices and networks 11->123 14 cmd.exe 1 11->14         started        16 certutil.exe 3 2 11->16         started        20 cmd.exe 1 11->20         started        22 3 other processes 11->22 process6 file7 24 pointer.com 1 8 14->24         started        57 C:\Users\Public\pointer.com, PE32 16->57 dropped 83 Drops PE files to the user root directory 16->83 85 Drops PE files with a suspicious file extension 16->85 29 conhost.exe 16->29         started        87 Uses ping.exe to sleep 20->87 31 PING.EXE 1 20->31         started        signatures8 process9 dnsIp10 79 dual-spov-0006.spov-msedge.net 13.107.137.11, 443, 49708, 49709 MICROSOFT-CORP-MSN-AS-BLOCKUS United States 24->79 61 C:\Users\Public\Libraries\truesight.sys, PE32+ 24->61 dropped 63 C:\Users\Public\Libraries\netutils.dll, PE32+ 24->63 dropped 65 C:\Users\Public\Libraries\easinvoker.exe, PE32+ 24->65 dropped 67 3 other malicious files 24->67 dropped 113 Early bird code injection technique detected 24->113 115 Machine Learning detection for dropped file 24->115 117 Drops PE files with a suspicious file extension 24->117 119 4 other signatures 24->119 33 colorcpl.exe 3 17 24->33         started        38 cmd.exe 1 24->38         started        81 127.0.0.1 unknown unknown 31->81 file11 signatures12 process13 dnsIp14 69 www.tarmacagraga.com 103.186.117.186, 2404, 49712, 49714 AARNET-AS-APAustralianAcademicandResearchNetworkAARNe unknown 33->69 71 geoplugin.net 178.237.33.50, 49713, 80 ATOM86-ASATOM86NL Netherlands 33->71 59 C:\ProgramData\yhujvtdr\logs.dat, data 33->59 dropped 97 Contains functionality to bypass UAC (CMSTPLUA) 33->97 99 Contains functionalty to change the wallpaper 33->99 101 Contains functionality to steal Chrome passwords or cookies 33->101 103 6 other signatures 33->103 40 Pgsyvkji.PIF 33->40         started        43 Pgsyvkji.PIF 33->43         started        45 MpCmdRun.exe 33->45         started        49 28 other processes 33->49 47 conhost.exe 38->47         started        file15 signatures16 process17 signatures18 105 Early bird code injection technique detected 40->105 107 Machine Learning detection for dropped file 40->107 109 Allocates memory in foreign processes 40->109 51 colorcpl.exe 40->51         started        111 Allocates many large memory junks 43->111 53 colorcpl.exe 43->53         started        55 conhost.exe 45->55         started        process19
Result
Malware family:
Score:
  10/10
Tags:
family:modiloader family:remcos botnet:better-year persistence rat trojan
Behaviour
Runs ping.exe
Script User-Agent
Suspicious behavior: CmdExeWriteProcessMemorySpam
Suspicious use of WriteProcessMemory
Program crash
Launches sc.exe
Adds Run key to start application
Executes dropped EXE
Loads dropped DLL
Creates new service(s)
ModiLoader Second Stage
NirSoft MailPassView
NirSoft WebBrowserPassView
Nirsoft
ModiLoader, DBatLoader
Remcos
Malware Config
C2 Extraction:
www.tarmacagraga.com:2404
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:MALWARE_BAT_KoadicBAT
Author:ditekSHen
Description:Koadic post-exploitation framework BAT payload

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments