MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3ea6307c607925c48b94aa06102187c9157527d70c69fb146c2904827a77162. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: d3ea6307c607925c48b94aa06102187c9157527d70c69fb146c2904827a77162
SHA3-384 hash: e5dc93ff295442075cd4db5aa2288893a5b4ef7cfc227b897032454a5f399a2bbab846debfa3565ad9485164c71834f2
SHA1 hash: 5659035fc298d484c37c06aa4cb816d254f201d7
MD5 hash: b163f86e0a052dc10597cbeae51de878
humanhash: gee-burger-kilo-south
File name:readme.exe
Download: download sample
Signature RemcosRAT
File size:814'594 bytes
First seen:2020-05-02 20:17:41 UTC
Last seen:2020-05-02 20:45:37 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash d6a7899ecfd259d4aa0e8ca93daa2768 (3 x GuLoader, 2 x RemcosRAT)
ssdeep 12288:v9/U2oV1xRKhWIBBWn7/Dazp/+0oeiKA/kJ1XI6GuF9UJUbZedjsDZHsCNXs:ve2eUBBWn7qN4e5MkfY/xdjKRsYs
Threatray 941 similar samples on MalwareBazaar
TLSH B7056D23F2D14837D5732A388C1B9B59A92ABE103D78AC457BF53D4C4F3A68178352A7
Reporter jarumlus
Tags:RemcosRAT

Intelligence


File Origin
# of uploads :
4
# of downloads :
96
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Delf
Status:
Malicious
First seen:
2020-05-02 20:35:22 UTC
File Type:
PE (Exe)
Extracted files:
70
AV detection:
27 of 31 (87.10%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_RemcosRAT
Author:abuse.ch
Rule name:win_remcos_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments