MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 cf4f6747108338afb07f27bfc880941015b7c75cb1759370ab942259f27abcdd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 16
| SHA256 hash: | cf4f6747108338afb07f27bfc880941015b7c75cb1759370ab942259f27abcdd |
|---|---|
| SHA3-384 hash: | 083731e573c4abc2f6de8cec9e9d8420e06357d59931057bb3bccbfb778179d88288835feb8fd62d4df225f233460e21 |
| SHA1 hash: | 90261a576d121fb94fa83e47316fc9a7f6376546 |
| MD5 hash: | 508844ec54f56fe9155db3b482a56a34 |
| humanhash: | one-nine-california-pasta |
| File name: | 508844ec54f56fe9155db3b482a56a34.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'258'264 bytes |
| First seen: | 2024-04-03 15:57:04 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 12e12319f1029ec4f8fcbed7e82df162 (389 x DCRat, 52 x RedLineStealer, 51 x Formbook) |
| ssdeep | 24576:3TbBv5rUDOs6aEYajgS7A9X4TFR7hwcuHfHfFGa6mPcyGJzQfs8FibyX1AS:RBVaEYaj+STFRhwPHsoGBQfo8x |
| TLSH | T15D451202BAC1A073C5B21C325EA66B21BA3D79201F718EDF63D4562DDE725D0D731BA2 |
| TrID | 89.0% (.EXE) WinRAR Self Extracting archive (4.x-5.x) (265042/9/39) 3.5% (.EXE) Win64 Executable (generic) (10523/12/4) 2.2% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 1.6% (.EXE) Win16 NE executable (generic) (5038/12/1) 1.5% (.EXE) Win32 Executable (generic) (4504/4/1) |
| File icon (PE): | |
| dhash icon | fab0a0a1b1d8f870 (2 x Rhadamanthys, 2 x RemcosRAT, 1 x Stealc) |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
39a8de9c02381c6b24ecc842826b1fa66ac585075d5419df30220fec264cf95d
e02090cd2eb0b654d0013fe4a8db53ee67fe570d25f5d3b520edc382bc84fb4f
cf4f6747108338afb07f27bfc880941015b7c75cb1759370ab942259f27abcdd
91aebaad56e80df4dbe148face0335070b4e7258afa67b5ded80f3370262c824
6905a9d5ffefb1d0c3f85002263c13698fa664f5d95a110263057880ac05ca1a
c1bf9e8d217baf7a33931f25d96ff9eab4c24f9702beaa41a91bcab3745a1875
0e412b9c0758edef5114ed627e60c09f4df2108942becdcaa3bc1cb30e439223
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | DebuggerCheck__API |
|---|---|
| Reference: | https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara |
| Rule name: | maldoc_find_kernel32_base_method_1 |
|---|---|
| Author: | Didier Stevens (https://DidierStevens.com) |
| Rule name: | RIPEMD160_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for RIPEMD-160 constants |
| Rule name: | SelfExtractingRAR |
|---|---|
| Author: | Xavier Mertens |
| Description: | Detects an SFX archive with automatic script execution |
| Rule name: | SHA1_Constants |
|---|---|
| Author: | phoul (@phoul) |
| Description: | Look for SHA1 constants |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
BLint
The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.
Findings
| ID | Title | Severity |
|---|---|---|
| CHECK_AUTHENTICODE | Missing Authenticode | high |
| CHECK_DLL_CHARACTERISTICS | Missing dll Security Characteristics (HIGH_ENTROPY_VA) | high |
Reviews
| ID | Capabilities | Evidence |
|---|---|---|
| GDI_PLUS_API | Interfaces with Graphics | gdiplus.dll::GdiplusStartup gdiplus.dll::GdiplusShutdown gdiplus.dll::GdipAlloc |
| WIN32_PROCESS_API | Can Create Process and Threads | KERNEL32.dll::CloseHandle KERNEL32.dll::CreateThread |
| WIN_BASE_API | Uses Win Base API | KERNEL32.dll::TerminateProcess KERNEL32.dll::LoadLibraryW KERNEL32.dll::LoadLibraryExA KERNEL32.dll::LoadLibraryExW KERNEL32.dll::GetSystemInfo KERNEL32.dll::GetStartupInfoW |
| WIN_BASE_EXEC_API | Can Execute other programs | KERNEL32.dll::AllocConsole KERNEL32.dll::AttachConsole KERNEL32.dll::WriteConsoleW KERNEL32.dll::FreeConsole KERNEL32.dll::SetStdHandle KERNEL32.dll::GetConsoleMode KERNEL32.dll::GetConsoleCP |
| WIN_BASE_IO_API | Can Create Files | KERNEL32.dll::CreateDirectoryW KERNEL32.dll::CreateHardLinkW KERNEL32.dll::CreateFileW KERNEL32.dll::CreateFileMappingW KERNEL32.dll::DeleteFileW KERNEL32.dll::MoveFileW KERNEL32.dll::MoveFileExW |
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.