MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d227f2c01b74856507e845738a6177dc8f2b5da7c56b8677fef9b11c7452bf22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d227f2c01b74856507e845738a6177dc8f2b5da7c56b8677fef9b11c7452bf22
SHA3-384 hash: cbc21957cc0b7faf3ee8bb5aad8cc10a4112401d820b8cb49913d730ba09362e90ced6fc437c0bf3cae6a093fe552787
SHA1 hash: a50675602689c48ad05010aea094c724d8821944
MD5 hash: 4563c1ba4e3759d5881228727fce684e
humanhash: fix-network-alabama-bakerloo
File name:attack.ps1
Download: download sample
Signature RemcosRAT
File size:5'019 bytes
First seen:2022-05-11 15:32:19 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 48:CBn6zALDCn/r4vGXKQuT4vGX1ebB7xxg8PzUPeSy3n5ZWibrE7xxpsGyN5nVJA7w:CB6zVnUujruYlxbnExLAexfqP1nPnx
Threatray 2'014 similar samples on MalwareBazaar
TLSH T1CFA112BAF684C5B0C61FE6398248BC1C0520BAC3C2D02DC467BC6C2A9C95FCF6D656C0
Reporter pr0xylife
Tags:ps1 RemcosRAT

Intelligence


File Origin
# of uploads :
1
# of downloads :
344
Origin country :
n/a
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
75%
Tags:
evasive powershell
Result
Verdict:
UNKNOWN
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
48 / 100
Signature
Malicious sample detected (through community Yara rule)
Behaviour
Behavior Graph:
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2022-05-11 15:33:05 UTC
File Type:
Text (PowerShell)
AV detection:
9 of 26 (34.62%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:remcos botnet:p1 rat
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Suspicious use of SetThreadContext
Loads dropped DLL
Blocklisted process makes network request
Remcos
Malware Config
C2 Extraction:
treatcode.dvrlists.com:3363
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments