MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f80ccdb5c9a3565a5fcfaddb71327a480648c9615687ecbfbc2dc93af1cb1d74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RemcosRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f80ccdb5c9a3565a5fcfaddb71327a480648c9615687ecbfbc2dc93af1cb1d74
SHA3-384 hash: 014917571e42f26606e21e59b4850805c0fe9f38877157a0df1955d72caa0ab660a106344b57618572f2ae26d5858bfe
SHA1 hash: a38cef93c17011a6ac82b981d5a5293cfd8c9598
MD5 hash: 23a8e6efbcd12679f115721e46b9d975
humanhash: vegan-nebraska-indigo-delaware
File name:INVOICE0980089.IMG
Download: download sample
Signature RemcosRAT
File size:137'934 bytes
First seen:2021-01-18 08:23:25 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 3072:JBzpzD86b+8qsL4fwQ8kaePG3/e9EIl66yfBoeD0:DNn86ba83G9dN
TLSH BCD312B37362EE09FFD33A5643957F2A4948999DFB41A0644958F046E34AF52C24B23C
Reporter abuse_ch
Tags:img RAT RemcosRAT


Avatar
abuse_ch
Malspam distributing RemcosRAT:

HELO: hosted-by.rootlayer.net
Sending IP: 185.222.58.152
From: shaik@sghcl.com.sa
Subject: Re: Invoice
Attachment: INVOICE0980089.IMG (contains "INVOICE0980089.exe")

RemcosRAT C2:
72.11.157.241:4445

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.Wacatac
Status:
Malicious
First seen:
2021-01-18 05:38:13 UTC
AV detection:
19 of 46 (41.30%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

RemcosRAT

zip f80ccdb5c9a3565a5fcfaddb71327a480648c9615687ecbfbc2dc93af1cb1d74

(this sample)

  
Dropping
RemcosRAT
  
Delivery method
Distributed via e-mail attachment

Comments