| File name: | remcos_a.exe |
| Full analysis: | https://app.any.run/tasks/76a9ed5c-d73d-4c4e-8fdb-97a5e984962a |
| Verdict: | Malicious activity |
| Threats: | Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis. Remcos ist eine Malware vom Typ RAT, mit der Angreifer aus der Ferne Aktionen auf infizierten Computern durchführen können. Diese Malware ist extrem aktiv und wird fast jeden Monat mit Updates auf den neuesten Stand gebracht. |
| Analysis date: | January 20, 2024, 20:46:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | remcos |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | D2A4237DA031B7D18B77A4015B1A36BB |
| SHA1: | D2406C3F0CFA21366DD7267DDCDCD405E2E6407F |
| SHA256: | 840FC6550D4FBAA21D3C66479574EB51C9859BFBF9C4C12366EC329AAD05A770 |
| SSDEEP: | 6144:YCJeAV9BKop4LoGdPtohtR7+lALpVjtaXEGr3TyM90TwVxqNXyu5rQWkcWVVVVVX:YCgIBLp4LoIWh/7+lALpBtaXEGrjETwL |
| .exe | | | UPX compressed Win32 Executable (64.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.6) |
| .exe | | | Win32 Executable (generic) (10.6) |
| .exe | | | Generic Win/DOS Executable (4.7) |
| .exe | | | DOS Executable Generic (4.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:26 10:44:26+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 196608 |
| InitializedDataSize: | 20480 |
| UninitializedDataSize: | 290816 |
| EntryPoint: | 0x77c50 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2044 | "C:\Users\admin\AppData\Local\Temp\remcos_a.exe" | C:\Users\admin\AppData\Local\Temp\remcos_a.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2044 | remcos_a.exe | 192.168.193.1:2404 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
