Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Remcos"
- * MalScore: 10.0
- * File Name: "remcos_f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce"
- * File Size: 126976
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce"
- * MD5: "214c35500a1154672ca73a228d035188"
- * SHA1: "70a3a4b28bcad2a006a72e609532d3abc6d7aaad"
- * SHA512: "1fd2482e092c009d2d54f1b1558dd1f718ea6e50fd9103f47e6a6fc141460246f8857cb5a8dc05c29eaa7eee90fbf2d13bf1016b4e9e3ba4cd3bb3825da0aa25"
- * CRC32: "89E6A7A4"
- * SSDEEP: "3072:djiTCiIMleBDfHllNUH80TCvRIdIYNGXm4OzOh6+rc+5:djiTCseB7HlPb0TyRIdIYNGX7OzOh6K"
- * Process Execution:
- "remcos_f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce.exe",
- "cmd.exe",
- "reg.exe",
- "wscript.exe",
- "cmd.exe",
- "remcos.exe",
- "cmd.exe",
- "reg.exe",
- "svchost.exe"
- * Executed Commands:
- "C:\\Windows\\System32\\cmd.exe /k %windir%\\System32\\reg.exe ADD HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v EnableLUA /t REG_DWORD /d 0 /f",
- "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs\"",
- "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs ",
- "C:\\Windows\\System32\\reg.exe ADD HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v EnableLUA /t REG_DWORD /d 0 /f",
- "\"C:\\Windows\\System32\\cmd.exe\" /c \"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\"",
- "cmd /c \"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\"",
- "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
- "C:\\Windows\\SysWOW64\\svchost.exe"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "remcos.exe tried to sleep 1435 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x000000f0, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x000001e8, length: 0x00000078"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x00018000, length: 0x00000020"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x00018058, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x000181a8, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x00018470, length: 0x00000010"
- "self_read": "process: wscript.exe, pid: 2300, offset: 0x00018640, length: 0x00000012"
- "self_read": "process: remcos.exe, pid: 1108, offset: 0x00000000, length: 0x0001f000"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "remcos_f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "remcos_f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs"
- "Process": "wscript.exe -> cmd"
- "Process": "remcos.exe -> C:\\Windows\\System32\\cmd.exe"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
- "Description": "Sniffs keystrokes",
- "Details":
- "SetWindowsHookExA": "Process: remcos.exe(1108)"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "remcos.exe(1108) -> svchost.exe(2404)"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
- "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\remcos"
- "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\logs.dat"
- "Description": "File has been identified by 57 Antiviruses on VirusTotal as malicious",
- "Details":
- "Bkav": "W32.KsieusJHZ.Trojan"
- "MicroWorld-eScan": "Generic.Malware.SL!.78475FDC"
- "FireEye": "Generic.mg.214c35500a115467"
- "CAT-QuickHeal": "Trojan.GenericPMF.S6960769"
- "McAfee": "GenericRXGN-WO!214C35500A11"
- "Malwarebytes": "Backdoor.Remcos"
- "SUPERAntiSpyware": "Backdoor.Remcos/Variant"
- "K7AntiVirus": "Trojan ( 0053ac2c1 )"
- "BitDefender": "Generic.Malware.SL!.78475FDC"
- "K7GW": "Trojan ( 0053ac2c1 )"
- "Cybereason": "malicious.00a115"
- "Arcabit": "Generic.Malware.SL!.D1328BFDC"
- "Invincea": "heuristic"
- "F-Prot": "W32/Rescoms.F.gen!Eldorado"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "ClamAV": "Win.Malware.Rescoms-6598304-0"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "NANO-Antivirus": "Trojan.Win32.Rescoms.fracvu"
- "Ad-Aware": "Generic.Malware.SL!.78475FDC"
- "Emsisoft": "Generic.Malware.SL!.78475FDC (B)"
- "Comodo": "TrojWare.Win32.Rescoms.B@7ijo3m"
- "F-Secure": "Backdoor.BDS/Backdoor.Gen"
- "DrWeb": "Trojan.DownLoader28.42322"
- "Zillya": "Trojan.Generic.Win32.854170"
- "TrendMicro": "BKDR_SOCMER.SM"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.ch"
- "Trapmine": "malicious.moderate.ml.score"
- "Sophos": "Troj/Remcos-DI"
- "Ikarus": "Backdoor.Remcos"
- "Cyren": "W32/Rescoms.F.gen!Eldorado"
- "Jiangmin": "Trojan.Generic.dkfka"
- "Avira": "BDS/Backdoor.Gen"
- "MAX": "malware (ai score=88)"
- "Antiy-AVL": "TrojanBackdoor/Win32.Rescoms"
- "Microsoft": "Backdoor:Win32/Rescoms.C!bit"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "GData": "Win32.Malware.Bucaspys.B"
- "AhnLab-V3": "Trojan/Win32.Generic.C3291877"
- "Acronis": "suspicious"
- "VBA32": "BScope.Backdoor.Rescoms"
- "ALYac": "Generic.Malware.SL!.78475FDC"
- "Cylance": "Unsafe"
- "Panda": "Trj/Genetic.gen"
- "ESET-NOD32": "a variant of Win32/Rescoms.B"
- "TrendMicro-HouseCall": "BKDR_SOCMER.SM"
- "Rising": "Backdoor.Remcos!1.B6A7 (CLASSIC)"
- "Yandex": "Trojan.Agent!KT8PzhB4DZI"
- "SentinelOne": "DFI - Malicious PE"
- "eGambit": "Unsafe.AI_Score_96%"
- "Fortinet": "W32/Agent.RXL!tr"
- "AVG": "Win32:RemcosRAT-A Trj"
- "Avast": "Win32:RemcosRAT-A Trj"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Qihoo-360": "HEUR/QVM07.1.585F.Malware.Gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Malware.Rescoms-6598304-0, sha256:f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Malware.Rescoms-6598304-0, sha256:f157f1b8de7a2ce7da0f9a120f9013bfa55b2e0119838c885af52028ae6a7fce , guest_paths:C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
- "Description": "Attempts to disable UAC",
- "Details":
- * Started Service:
- * Mutexes:
- "Remcos_Mutex_Inj",
- "Remcos-L39JAZ",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "Mutex_RemWatchdog"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
- "C:\\Users\\user\\AppData\\Roaming\\remcos\\logs.dat"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
- "HKEY_CURRENT_USER\\Software\\Remcos-L39JAZ\\",
- "HKEY_CURRENT_USER\\Software\\Remcos-L39JAZ\\exepath",
- "HKEY_CURRENT_USER\\Software\\Remcos-L39JAZ\\licence",
- "HKEY_CURRENT_USER\\Software\\Remcos-L39JAZ\\WD"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Remcos-L39JAZ\\WD"
- * DNS Communications:
- "type": "A",
- "request": "pecunia11223344.warzonedns.com",
- "answers":
- "data": "192.34.109.202",
- "type": "A"
- * Domains:
- "ip": "192.34.109.202",
- "domain": "pecunia11223344.warzonedns.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment