MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc616be368a1ef32f7ff04b0e96c3a519e56759d8fc9766455bf65a2aa7ae0c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: dc616be368a1ef32f7ff04b0e96c3a519e56759d8fc9766455bf65a2aa7ae0c4
SHA3-384 hash: be2255f5aeea4717a72db6a768ddcb754477da30d5060aaf12a5f5ec7c3d951d4d59a3d071b0fa7cd980d9d2aacd80ab
SHA1 hash: df9800b90d68624fe7b18f9ce8251aab02d41cf7
MD5 hash: d07bd4f5c6cd2909b7fcd6a321dbad8e
humanhash: carolina-gee-lactose-tango
File name:要求報價 6894_.IMG
Download: download sample
Signature RemcosRAT
File size:1'245'184 bytes
First seen:2020-05-05 09:16:18 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 3072:wKfYokQWCWdN7LtS2b7h+wHXwZccUkX0D5sCaXxVlwZfEJe6oBWqFsOnd316zf2Q:wKfYUOM2keN9UtwyJxqHd31vDAzWJl
TLSH AA450285DA080966C9B45B7998B74E05023FAE7AB4F6A31F7D6DF1202FB73C35421827
Reporter abuse_ch
Tags:img RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: sip2-180.nexcess.net
Sending IP: 104.207.224.7
From: procurement@ot.mn
Subject: 要求報價
Attachment: 要求報價 6894_.IMG (contains "要求報價 6894_IMG.exe")

RemcosRAT C2:
172.94.44.202:6606

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-05 02:41:42 UTC
File Type:
Binary (Archive)
AV detection:
18 of 31 (58.06%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

img dc616be368a1ef32f7ff04b0e96c3a519e56759d8fc9766455bf65a2aa7ae0c4

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments