MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0d40295670029f8bbfdf4816ceded979979e4c1e1ec5be0d6395dce228b6c68. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: e0d40295670029f8bbfdf4816ceded979979e4c1e1ec5be0d6395dce228b6c68
SHA3-384 hash: 14c01210b02c966128c7d7eebe56074d0b89ba469c092790a722fd71c3f3a22a15f37623323af2b7d24df645a08de9d1
SHA1 hash: 50699e22543b6ec1c35a5dbec365eb277f7acd94
MD5 hash: 09401095d969ae52da6315f14ee73bcc
humanhash: beryllium-six-kitten-speaker
File name:Draft BLs BL No UIH000062500.z
Download: download sample
Signature RemcosRAT
File size:483'579 bytes
First seen:2020-10-26 14:17:33 UTC
Last seen:Never
File type: z
MIME type:application/x-rar
ssdeep 12288:CaLZ4gwxmghRpwbzN/p7iHWsDw7yDcA4w1jHUwa:hLZ4vwxp78Zsyv4Ge
TLSH 5CA423812FEE06B052EF0D38A949502BD588E20FD6DD934DE27A6F4C93F65B6351B21C
Reporter abuse_ch
Tags:RAT RemcosRAT z


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: uih.pilship.com
Sending IP: 104.129.30.185
From: AM MARY NHAN <mary@uih.pilship.com>
Subject: Draft B/L(s) (B/L No : UIH000062500)
Attachment: Draft BLs BL No UIH000062500.z (contains "Draft BL(s) (BL No UIH000062500).exe")

RemcosRAT C2:
104.207.150.47:2010

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

z e0d40295670029f8bbfdf4816ceded979979e4c1e1ec5be0d6395dce228b6c68

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments