MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
RemcosRAT
Vendor detections: 16
| SHA256 hash: | f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e |
|---|---|
| SHA3-384 hash: | 697b5dd055ed11b2a334e3aa3107fcdbe2d2f4c48c6b6fa2827a52f2024c917ca67f3ab36970a9856f1554cb4bbe3319 |
| SHA1 hash: | 97fa10f1583063635f6bdb9a366062848fe3bd78 |
| MD5 hash: | 0f48cb3182a6fbf4fe385465b6d7c795 |
| humanhash: | nineteen-ack-eleven-zulu |
| File name: | 0f48cb3182a6fbf4fe385465b6d7c795.exe |
| Download: | download sample |
| Signature | RemcosRAT |
| File size: | 1'029'120 bytes |
| First seen: | 2023-06-30 07:10:16 UTC |
| Last seen: | Never |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | f34d5f2d4577ed6d9ceec516c1f5a744 (48'648 x AgentTesla, 19'452 x Formbook, 12'201 x SnakeKeylogger) |
| ssdeep | 24576:p7+zoYbLtOZAK9nB/rv9EdPWA4rbtQQB:pKNOZV9nB/79EZWFrb6Q |
| Threatray | 2'343 similar samples on MalwareBazaar |
| TLSH | T1ED25AC3829BDA32BD174D7F48FD58023F7A4952B3026EAE5ACC257994752F1225C323E |
| TrID | 71.1% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13) 10.2% (.EXE) Win64 Executable (generic) (10523/12/4) 6.3% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 4.3% (.EXE) Win32 Executable (generic) (4505/5/1) 2.0% (.ICL) Windows Icons Library (generic) (2059/9) |
| File icon (PE): | |
| dhash icon | d2929c9c9cd8e0f0 (5 x AgentTesla, 2 x RemcosRAT, 1 x Formbook) |
| Reporter | |
| Tags: | exe RAT RemcosRAT |
Intelligence
File Origin
NLVendor Threat Intelligence
Result
Behaviour
Result
Details
Result
Signature
Behaviour
Result
Behaviour
Malware Config
Unpacked files
8e861cbf43bd4068930cb5ef3821cab163fad49d42b77c66b70fff8fa038db48
ca19795538ded5ca26ae167d5417cc200d51ff7738e36695fbb05b305dbc15b6
9e6406269fe3e1f7a309e3ee01e4770d6f5c7abd2dead9afc7eddfedcdb04295
38106a2209026f52e0be443c19aa6f520ced381b00ce20ab78d547475cc24872
5e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920ae
a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40
34bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1
df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4ba
f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e
49e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6
49e64d72d5ed4fb7967da4b6851d94cdceffe4ba0316587767a13901fe580239
99ed6e63a6e0562da0a4accc3c868a50a04e5c4f7757c99808eddf6979b84587
8e861cbf43bd4068930cb5ef3821cab163fad49d42b77c66b70fff8fa038db48
ca19795538ded5ca26ae167d5417cc200d51ff7738e36695fbb05b305dbc15b6
9e6406269fe3e1f7a309e3ee01e4770d6f5c7abd2dead9afc7eddfedcdb04295
38106a2209026f52e0be443c19aa6f520ced381b00ce20ab78d547475cc24872
5e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920ae
a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40
34bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1
df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4ba
f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e
49e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6
49e64d72d5ed4fb7967da4b6851d94cdceffe4ba0316587767a13901fe580239
99ed6e63a6e0562da0a4accc3c868a50a04e5c4f7757c99808eddf6979b84587
8e861cbf43bd4068930cb5ef3821cab163fad49d42b77c66b70fff8fa038db48
ca19795538ded5ca26ae167d5417cc200d51ff7738e36695fbb05b305dbc15b6
9e6406269fe3e1f7a309e3ee01e4770d6f5c7abd2dead9afc7eddfedcdb04295
38106a2209026f52e0be443c19aa6f520ced381b00ce20ab78d547475cc24872
5e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920ae
a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40
34bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1
df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4ba
f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e
49e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6
49e64d72d5ed4fb7967da4b6851d94cdceffe4ba0316587767a13901fe580239
99ed6e63a6e0562da0a4accc3c868a50a04e5c4f7757c99808eddf6979b84587
8e861cbf43bd4068930cb5ef3821cab163fad49d42b77c66b70fff8fa038db48
ca19795538ded5ca26ae167d5417cc200d51ff7738e36695fbb05b305dbc15b6
9e6406269fe3e1f7a309e3ee01e4770d6f5c7abd2dead9afc7eddfedcdb04295
38106a2209026f52e0be443c19aa6f520ced381b00ce20ab78d547475cc24872
5e95168687b15de3724b3c8240c0b40cdb61c75b440d11a7fa72c2b247c920ae
a8ae7002d16df08878c864f8cd2f8722dfcb5950372f3b12c88f4e265f2eee40
34bfed7f2450542d851b696685ed0a43438683a54f1756a947119d7258a4adb1
df906c77d802e4e977ff24b11e1840d6948338250023a27b2b30ad9ac6e3f4ba
f60667b9e2a0a25221cdb47844149beb3b1cd08abbc3360e8684fad9d8aaa20e
49e4d4f6aaf967b656487d0d3dc27ecf3812b2d454b85339ae9ea79021bbe0d6
49e64d72d5ed4fb7967da4b6851d94cdceffe4ba0316587767a13901fe580239
99ed6e63a6e0562da0a4accc3c868a50a04e5c4f7757c99808eddf6979b84587
YARA Signatures
MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.
| Rule name: | pe_imphash |
|---|
| Rule name: | Skystars_Malware_Imphash |
|---|---|
| Author: | Skystars LightDefender |
| Description: | imphash |
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Web download
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.