MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f5b86bcb2e58400f938e94c71a1b1e7b06d6e9bc1749fc1e6f999110e4fc9143. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 16
| SHA256 hash: | f5b86bcb2e58400f938e94c71a1b1e7b06d6e9bc1749fc1e6f999110e4fc9143 |
|---|---|
| SHA3-384 hash: | ea3355d47c603704c56336483a38fb8ffcbcdf3600076ac5ca8a9f9f491fbaee3c4673e03cb5c6f487ec53d9278dbecc |
| SHA1 hash: | f73b55b3036bf1a83c4ca96ed914e1d1ba669f2d |
| MD5 hash: | 8a64c958def4abbd468d5bc040da7567 |
| humanhash: | steak-colorado-echo-rugby |
| File name: | SecuriteInfo.com.Win32.RATX-gen.32756.13152 |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'055'744 bytes |
| First seen: | 2023-01-10 04:28:12 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'452 x Formbook, 12'202 x SnakeKeylogger) |
| ssdeep | 24576:AIOWbQRdD19C3yUJxWZsJYYqEZV/NWCagfzF:nbo19CtEqBqEZVAgf |
| Threatray | 4'150 similar samples on MalwareBazaar |
| TLSH | T14D25023526E9B85EFD7E63FB5311CA5403B1A520C749E6DD0DAB26CFCAF8A198207113 |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | 00c0c8c1e6789842 (4 x AgentTesla, 3 x RemcosRAT, 1 x SnakeKeylogger) |
| Reporter | |
| Tags: | exe RemcosRAT |
Intelligence
File Origin
Vendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
24e038fe958537de3ac2de0792131ae1cb08c1564801e0d95cee02281fb6e724
f5b86bcb2e58400f938e94c71a1b1e7b06d6e9bc1749fc1e6f999110e4fc9143
abe27f90a49a7e563fc39eb1e0da5c0327e490aefe6638fa4dfa50fea16c42d2
3e5978c46162ecb05c51d7fff9ec6786ac453fff4dba91d906f9ec2f764d87af
d17ccb455ee24cc30f0bb0bdbfe244a388444b82ec069bb0766870b243f03695
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.