MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 18


Intelligence 18 IOCs YARA 17 File information Comments

SHA256 hash: b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
SHA3-384 hash: 3344f1c2d76845212a773d4fcbfca6ca934d4f7f6f811e335d23c95e764a28df272d09c281e67c0521337a606f1aeabe
SHA1 hash: 20d348837ef05b6ed0eccd3300fce74c8038c599
MD5 hash: 9af50ddc8887f5389642c602ab333581
humanhash: sweet-yankee-paris-purple
File name:ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe
Download: download sample
Signature RemcosRAT
File size:915'968 bytes
First seen:2024-04-06 09:53:24 UTC
Last seen:2024-04-06 09:54:40 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'652 x AgentTesla, 19'463 x Formbook, 12'204 x SnakeKeylogger)
ssdeep 24576:bHYmq2tNBlF1qaf1etRc/dZeBrHO3ein9mUO:DYUtNBlP1etRcVZeBrupo/
Threatray 701 similar samples on MalwareBazaar
TLSH T195152236BFAFED26C1BA673EC16615091372E74B1263E7432DCC036D121A7DA4D89E06
TrID 67.7% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
9.7% (.EXE) Win64 Executable (generic) (10523/12/4)
6.0% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
4.6% (.EXE) Win16 NE executable (generic) (5038/12/1)
4.1% (.EXE) Win32 Executable (generic) (4504/4/1)
Reporter cocaman
Tags:exe RemcosRAT RFQ

Intelligence


File Origin
# of uploads :
2
# of downloads :
305
Origin country :
CH CH
Vendor Threat Intelligence
Malware family:
ID:
1
File name:
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c.exe
Verdict:
Malicious activity
Analysis date:
2024-04-06 09:54:54 UTC
Tags:
rat remcos remote keylogger stealer

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %AppData% directory
Enabling the 'hidden' option for recently created files
Adding an access-denied ACE
Creating a process with a hidden window
Creating a file in the %temp% directory
Launching a process
Unauthorized injection to a recently created process
Restart of the analyzed sample
Creating a file
Setting a keyboard event handler
DNS request
Creating a file in the %AppData% subdirectories
Connection attempt
Sending a custom TCP request
Sending an HTTP GET request
Reading critical registry keys
Stealing user critical data
Adding an exclusion to Microsoft Defender
Enabling autorun by creating a file
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
masquerade net_reactor packed packed remcos
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Remcos, PureLog Stealer
Detection:
malicious
Classification:
rans.phis.troj.spyw.expl.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Adds a directory exclusion to Windows Defender
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Antivirus detection for URL or domain
C2 URLs / IPs found in malware configuration
Contains functionality to bypass UAC (CMSTPLUA)
Contains functionality to register a low level keyboard hook
Contains functionality to steal Chrome passwords or cookies
Contains functionality to steal Firefox passwords or cookies
Contains functionalty to change the wallpaper
Delayed program exit found
Detected Remcos RAT
Found malware configuration
Initial sample is a PE file and has a suspicious name
Injects a PE file into a foreign processes
Installs a global keyboard hook
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Maps a DLL or memory area into another process
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Remcos
Sigma detected: Scheduled temp file as task from temp location
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Instant Messenger accounts or passwords
Tries to steal Mail credentials (via file / registry access)
Tries to steal Mail credentials (via file registry)
Uses schtasks.exe or at.exe to add and modify task schedules
Writes many files with high entropy
Yara detected AntiVM3
Yara detected PureLog Stealer
Yara detected Remcos RAT
Yara detected UAC Bypass using CMSTP
Yara detected WebBrowserPassView password recovery tool
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1421298 Sample: ORDER RFQ ICPO TECNOMAT-JEA... Startdate: 06/04/2024 Architecture: WINDOWS Score: 100 56 paygateme.net 2->56 58 geoplugin.net 2->58 70 Multi AV Scanner detection for domain / URL 2->70 72 Found malware configuration 2->72 74 Malicious sample detected (through community Yara rule) 2->74 76 20 other signatures 2->76 8 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 7 2->8         started        12 mmznklFQRO.exe 5 2->12         started        signatures3 process4 file5 44 C:\Users\user\AppData\...\mmznklFQRO.exe, PE32 8->44 dropped 46 C:\Users\user\AppData\Local\...\tmpF805.tmp, XML 8->46 dropped 78 Adds a directory exclusion to Windows Defender 8->78 80 Injects a PE file into a foreign processes 8->80 14 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 3 1014 8->14         started        19 powershell.exe 23 8->19         started        21 schtasks.exe 1 8->21         started        82 Antivirus detection for dropped file 12->82 84 Multi AV Scanner detection for dropped file 12->84 86 Contains functionality to bypass UAC (CMSTPLUA) 12->86 88 6 other signatures 12->88 23 mmznklFQRO.exe 12->23         started        25 schtasks.exe 12->25         started        signatures6 process7 dnsIp8 60 paygateme.net 146.70.57.34, 2286, 49709, 49710 TENET-1ZA United Kingdom 14->60 62 geoplugin.net 178.237.33.50, 49711, 80 ATOM86-ASATOM86NL Netherlands 14->62 48 C:\Users\user\...\time_20250130_040555.dat, data 14->48 dropped 50 C:\Users\user\...\time_20250130_032601.dat, data 14->50 dropped 52 C:\Users\user\...\time_20250130_022855.dat, data 14->52 dropped 54 498 other malicious files 14->54 dropped 64 Detected Remcos RAT 14->64 66 Maps a DLL or memory area into another process 14->66 68 Installs a global keyboard hook 14->68 27 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 14->27         started        30 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 14->30         started        32 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 14 14->32         started        34 ORDER RFQ ICPO TECNOMAT-JEAL-EN590-200KMT-RTDM+TSA.exe 14->34         started        36 WmiPrvSE.exe 19->36         started        38 conhost.exe 19->38         started        40 conhost.exe 21->40         started        42 conhost.exe 25->42         started        file9 signatures10 process11 signatures12 90 Tries to steal Instant Messenger accounts or passwords 27->90 92 Tries to steal Mail credentials (via file / registry access) 27->92 94 Tries to harvest and steal browser information (history, passwords, etc) 30->94
Threat name:
Win32.Trojan.Leonem
Status:
Malicious
First seen:
2024-04-05 06:36:12 UTC
File Type:
PE (.Net Exe)
Extracted files:
11
AV detection:
19 of 36 (52.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:remotehost collection rat spyware stealer
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Suspicious use of SetThreadContext
Accesses Microsoft Outlook accounts
Checks computer location settings
Reads user/profile data of web browsers
NirSoft MailPassView
NirSoft WebBrowserPassView
Nirsoft
Remcos
Malware Config
C2 Extraction:
paygateme.net:2286
Unpacked files
SH256 hash:
71dab87ac5b7b80468ef8ccb16b74b39cc862b7fb9a6e430e4cd7e375dbe6c27
MD5 hash:
df9e546ebe70f8307bc8e6ad3aa08f0f
SHA1 hash:
d649fef8643e0a0c870519420522d5ca23dd7382
Detections:
INDICATOR_EXE_Packed_SmartAssembly
Parent samples :
498b4a265a27f8362fea4fcf15a184b220475c891249c892406030eb3b245c00
79e473fb7f021d7b394ac013c2abcca1a094a918b6f2edb48c0ed18d7b3b7460
53ffe79bd4c176d257a5b0a5a147ecaa522356d3ea80ab83dc6f8c55bd545c08
2d4255b15429696714b3c6e55077d3d95cfbc71a746406385cc4ba5025eb6a45
da6f3f1f642c13d2b7bf4c86e2686c5e1b606dbe0838423998c15742940545e9
a48b8a6ca726f32569a7e2041803898a902437ee7724da53accfb6dc52fa8a87
c94be0d3693316359c2e48e43baf51dff4f0b8d5efab6050962a09ef46ead4dc
24798002b81be4c9b37539e1abea61cccb014cbd427fe1a27d6822e1ffedc7d9
9fc2770fbd67c9b6f9f244ac6ac0fa8810c3d50e08c7d77b332bf1447ab77fab
2c8008052d15b5a7a61808357f2085226f7f9bc9619bb2040c27024a6423b9d2
1ba9c4dfbdfb55f6588c8887006f2851716eb6e53eb2bd1bccd591aa9e182da7
413bf66fb3f4c507d5e04fcd975056619d5874af3b92fa59eb9db52d18e2928b
38f97adf003d63f84a6c5bc35c9d9096901e7292e763bd9fbeabdafa1aa5fa78
12f1562e82415f8f320bc830dc6047870ea78ceb7e827af394dbe428d8ebc930
450160aa7afe149bc82992b2dd8f44fdaf64fcaec24d7b9c8522251f538a7636
859876f4be1e8206802a3468eb52a143bf5bc15724c0b66b70d98edd79c06a08
f48dfafeefb4b36315d6b8f987df1026d29c102bd24703a08cc4d4d41a483505
5408e8b840c407984e92034c26e937b1785c5f4b6762b14f2f7a31cec4d982d8
74a07ee3f0060987ebcb09e588ac1299a9d2a19e2f4139385f7880c229e2c8cf
da1903e676a7609f931a23ef7a653af4c1be9ef5242a80bdca67cb076d372bfd
cf432fc47407df80dcf984cf5d8d1a6aaed7c8c2a4c9b3a76627b4194bb9c782
73c44dbb7ece4e2fee17409d2d0ebcc82a77dd86c7ab0c9da9d8453cab59fbcc
c161b936b669673a3441c19755270abebe800846e8a01be9477e634d91b44635
191239a61c70ba900694d294a164f4a162b84d11672871fbb5389967bbf52c7e
ff2ae4fd71daa1a98edd5f88b743a5daa5fb29f70b87dee08fec25313a3640f1
554b40336bad24df88cbde544cdf20d553d02ce7fee5dab9a82318d7c21471e0
bc5f1294caaee05297ad1547f2f6ec4a309c16f7caf906f21038269d72f54957
15df84ca3a0c112b7ab461d6ee7603fcec8e24da91d4042d3ab018f87530b6ac
32aeea1990475960922b9a0bbda5a7edc864a3c70e4b8c5e84b16e269ea6fc7c
677f5939951053c165cdff92b6fa68d53748365869a978b77c2a501a46d1c4c8
67a792fced715c64610c55d8c01b16d66080c10004ed572e664c324468afdd7d
02a5ec5d9037cdd26b3f1ade8ea4028fbd0947284bfb3d7649e065d22db0ef91
704427aa451d261a1a92a6e834a1ee2be50971a012e711f9f660403904a9622c
6fd8e845cfa1bf8f809f0f372c2d4e955c6a3b6c0e88fb8f474a2645f587ecf0
9f6eb9b6b3bf92a75e32208dd51ce6307fa5ccdae27f02f0c7e2712544c2c04f
8506e0fdcf9ce49bd939a62bacd3e4d1af3522d72e660382684b1e4d1bb8e6b7
8fb359ccf3a3b6a0eff8204f9ee27c2dc41b3270721716192a7ef9253453b59b
8f53280f0b7807f08cf03152768d385200db1ad864b256fd9e7decbc846b05a2
70517116e2400906af6125849ac27b66159a45f6f1782178351e82bfe5ba205c
1711d935991cb37bd208dec08aefb47cf049baa4aa465d3188feccd8d330e72d
b1a574a7a0aad03e9f0a8470fd53013c565e67461ff21fc79e1bb6205974adb1
190504e991bb8bb608cf87db9ee7c7549999a17970251490ce85282f85cb49aa
f4eaa74eb268a58cff6f5d37607758bd49cc00af060da799857ae10cfd59efb2
8243f0400ffe13c6d332e0ab70af833ae44e446a5419f411a5c2586c86c51277
2a0a27371b6f4d355c3264fcc668d8a0fe1af7ebb8b19dca3b5cdf20a3282d65
f486a970c3228b346008eb169500d373560ea047084818b77357ba68bfa960af
8f02ecb26530c0a13b7f00020ebca144fc271fe36a5caaba1f4b3270e8e0023c
bd7f924e17174165e42ee077f973be26f07c6653ff33951ff9c53fb7cc833bae
1dea51f5680fedc83402ccb9401ae907c9493ef8625a76fe6f6cd9f475021e6a
a433dfdb99b293b73898ac05be0fbf6baa9d79976655b0c51ba5a5a0066a2632
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
da86da7fc086aa8262222feed9f4cd4df4c4538e77d90a7c160b1c794f298b92
ef8ad9042176ddf7dae5199f0135c2efabf224a45ac52f0ebc054b7ee9806c04
efb67364fa543ceddc607094c10c4b71f3baac1f45de5c2c759c489f97a64ec2
47cf473f0a0c146e5ae4a37b987c297be41d82af40d53e4dc750ca9b66fa7ea6
9d1f9f7012962df24baa3c3ac0816333abecf2a433953f68dab7e7673fac59aa
4b4c3585bbf95af33fac18ae92347069e2b732626cc6c7984ebfef92ea0a89b0
31fea186e7379793d1d9b37d2a981ed0fb05d40ee7d62e227eac695106ebbe2f
d23bd1fbaae83547ec6aba06ad8b4eef5119bd4a0f66634a6726b6ccd5dc3c78
dd14afafbf11a0251a0c5c56b3ef8b0be205cd4ed5d70fe77df7fdc90a039a4a
36ea8608df9b009caf566d4309832531c532d9eaf5c28b5b1657acf54c471209
95e4dd6cc5a341f4440a113e0a832175aa2f5baafd9c7483255a18088e1c2764
44ba13a119d19891a586d95310d8a51e9440fe2c1659b397d5795ecab37e3eeb
SH256 hash:
f4b0f58a64d77437a2a1a02ac2a051e335e28990b9f499a0ea50ab68ad35adfe
MD5 hash:
b25cad8b1780ef8b07454af6bc7e649e
SHA1 hash:
632c4df60d87758925bd1e7a8786bcfb7f84698d
SH256 hash:
14641f03051d346aa3a24be14851261baa2ee6b1cff524ddca433fcc71d9542d
MD5 hash:
6661bfd44985279631496543484323b1
SHA1 hash:
5b3452b4c01b676f5ab2d4586819bd687456a34e
SH256 hash:
b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c
MD5 hash:
9af50ddc8887f5389642c602ab333581
SHA1 hash:
20d348837ef05b6ed0eccd3300fce74c8038c599
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerCheck__QueryInfo
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:iexplorer_remcos
Author:iam-py-test
Description:Detect iexplorer being taken over by Remcos
Rule name:INDICATOR_SUSPICIOUS_EXE_UACBypass_CMSTPCOM
Author:ditekSHen
Description:Detects Windows exceutables bypassing UAC using CMSTP COM interfaces. MITRE (T1218.003)
Rule name:maldoc_find_kernel32_base_method_1
Author:Didier Stevens (https://DidierStevens.com)
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_imphash
Rule name:PureCrypter
Author:@bartblaze
Description:Identifies PureCrypter, .NET loader and obfuscator.
Reference:https://malpedia.caad.fkie.fraunhofer.de/details/win.purecrypter
Rule name:Remcos
Author:kevoreilly
Description:Remcos Payload
Rule name:REMCOS_RAT_variants
Rule name:Skystars_Malware_Imphash
Author:Skystars LightDefender
Description:imphash
Rule name:ThreadControl__Context
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:Windows_Trojan_Remcos_b296e965
Author:Elastic Security
Reference:https://www.elastic.co/security-labs/exploring-the-ref2731-intrusion-set
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.remcos.
Rule name:win_remcos_w0
Author:Matthew @ Embee_Research
Description:Detects strings present in remcos rat Samples.
Rule name:yarahub_win_remcos_rat_unpacked_aug_2023
Author:Matthew @ Embee_Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

Executable exe b1f7d2a6fee6eb162c9e154b565ee6fe95c6e03fa15bef35d8c14663b844087c

(this sample)

  
Delivery method
Other

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_DLL_CHARACTERISTICSMissing dll Security Characteristics (HIGH_ENTROPY_VA)high

Comments