MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f410f3c323f5a27d2dd922d914e7fa8d7c8e8199d84ed2ce35d51464c8a3c71b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f410f3c323f5a27d2dd922d914e7fa8d7c8e8199d84ed2ce35d51464c8a3c71b
SHA3-384 hash: 5525efe69bbe19048b15cd086d06ea40c799f8ec5660e532c9b0ceb82fec670fd2b35a9f2a2e75a9874d72ae4f08a679
SHA1 hash: 51797c8688df5dfc1486f86efa5214a0a311a6ef
MD5 hash: 09602aab2bba67edb0a1dbd83b80bf24
humanhash: texas-minnesota-hydrogen-coffee
File name:Quotation_768.PDF.zip
Download: download sample
Signature RemcosRAT
File size:523'843 bytes
First seen:2021-02-08 14:54:22 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 12288:HuOJd0pfMQHdo1wblftLLNabp2YeNFJDji3Sfq/uEB:HdEpfuyblftLLNapN3buEB
TLSH 1CB423B67807D2F9B05E9C5DB50258BF5FBA0A0CC230DB21B985DF4D23AAE13646617C
Reporter abuse_ch
Tags:nVpn RAT RemcosRAT zip


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: c.ccs.org.cn
Sending IP: 36.110.92.137
From: 任彦胜<renyansheng@c.ccs.org.cn>
Subject: Request_For_Quotation SWP-08_02_2021-QDRG5853
Attachment: Quotation_768.PDF.zip (contains "Quotation_768.PDF.exe")

telnet 185.140.53.192 20944

Intelligence


File Origin
# of uploads :
1
# of downloads :
245
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-02-08 14:55:08 UTC
AV detection:
18 of 47 (38.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip f410f3c323f5a27d2dd922d914e7fa8d7c8e8199d84ed2ce35d51464c8a3c71b

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments