URL:

https://breakingsecurity.net/wp-content/uploads/dlm_uploads/2018/03/Remcos-v4.9.3-Pro.zip

Full analysis: https://app.any.run/tasks/b5a343a5-b3d2-4f1b-a3f1-26ab1996fc4f
Verdict: Malicious activity
Analysis date: February 10, 2024, 19:31:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

E9844E6B517D75F0C993F6303AD81D96

SHA1:

740D828BEE23A9ADAACFD0AB20300EAF81ACE50C

SHA256:

F1FA33FFC6962426E7098ED0A2E8D8E7CD1B7065C65EA5920C936D2693625A28

SSDEEP:

3:N8eM2WrRFRbOlAQy/HAhXSKwIUITRWWxrUn:232cRFRbOlAZfyihIUu/NUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Remcos v4.9.3 Pro.exe (PID: 2064)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Reads the Internet Settings

      • Remcos v4.9.3 Pro.exe (PID: 2064)
  • INFO

    • Modifies the phishing filter of IE

      • iexplore.exe (PID: 3656)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 3960)
      • iexplore.exe (PID: 3656)
    • Application launched itself

      • iexplore.exe (PID: 3656)
      • firefox.exe (PID: 1352)
      • firefox.exe (PID: 2724)
      • iexplore.exe (PID: 3432)
    • Checks supported languages

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Manual execution by a user

      • Remcos v4.9.3 Pro.exe (PID: 2064)
      • firefox.exe (PID: 1352)
      • explorer.exe (PID: 2636)
      • iexplore.exe (PID: 3432)
    • Reads the computer name

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Checks proxy server information

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Reads the machine GUID from the registry

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Reads product name

      • Remcos v4.9.3 Pro.exe (PID: 2064)
    • Reads Environment values

      • Remcos v4.9.3 Pro.exe (PID: 2064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
16
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe winrar.exe no specs remcos v4.9.3 pro.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs explorer.exe no specs iexplore.exe iexplore.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
296"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.2.24295201\1260471687" -childID 1 -isForBrowser -prefsHandle 2064 -prefMapHandle 2060 -prefsLen 28712 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {0183bed3-7670-4f7c-ab5b-67407e97958a} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 2076 12d3e560 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
324"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.5.862651404\71274905" -childID 4 -isForBrowser -prefsHandle 3944 -prefMapHandle 3844 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {7e171a16-83c6-4a6e-89fe-eacfac1fc2aa} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 3948 1935e280 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
492"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.0.1274099969\1058963226" -parentBuildID 20230710165010 -prefsHandle 1116 -prefMapHandle 1108 -prefsLen 28523 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {6dff4ed1-5edb-4e62-a328-a73a48e7903b} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 1188 d6a71a0 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
1
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
668"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.4.1544453248\1158686838" -childID 3 -isForBrowser -prefsHandle 3496 -prefMapHandle 3500 -prefsLen 29209 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {e9dda0e4-701c-42e3-b6c9-42975ce79604} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 3376 1832eb20 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
1352"C:\Program Files\Mozilla Firefox\firefox.exe" C:\Program Files\Mozilla Firefox\firefox.exeexplorer.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2064"C:\Users\admin\Desktop\Remcos v4.9.3 Pro.exe" C:\Users\admin\Desktop\Remcos v4.9.3 Pro.exe
explorer.exe
User:
admin
Company:
BreakingSecurity.net
Integrity Level:
MEDIUM
Description:
REMCOS Remote Control & Surveillance
Exit code:
0
Version:
4.9.3.0
Modules
Images
c:\users\admin\desktop\remcos v4.9.3 pro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2096"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.1.1096668296\1936187182" -parentBuildID 20230710165010 -prefsHandle 1420 -prefMapHandle 1416 -prefsLen 28600 -prefMapSize 244195 -appDir "C:\Program Files\Mozilla Firefox\browser" - {45c6288f-3451-492c-bb43-70fd166b110c} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 1432 d614390 socketC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2616"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2724.3.1029315035\278041649" -childID 2 -isForBrowser -prefsHandle 2888 -prefMapHandle 2884 -prefsLen 34225 -prefMapSize 244195 -jsInitHandle 888 -jsInitLen 240908 -parentBuildID 20230710165010 -appDir "C:\Program Files\Mozilla Firefox\browser" - {ae7dfd00-07d2-4add-b7e9-2fce6e04c598} 2724 "\\.\pipe\gecko-crash-server-pipe.2724" 2900 169a1280 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
2636"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2724"C:\Program Files\Mozilla Firefox\firefox.exe"C:\Program Files\Mozilla Firefox\firefox.exe
firefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
0
Version:
115.0.2
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
Total events
46 699
Read events
46 330
Write events
284
Delete events
85

Modification events

(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
1
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchLowDateTime
Value:
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
31087703
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31087703
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(3656) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
2
Suspicious files
83
Text files
48
Unknown types
69

Dropped files

PID
Process
Filename
Type
3720iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Remcos-v4.9.3-Pro.zip.uednp5o.partial
MD5:
SHA256:
3656iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\Remcos-v4.9.3-Pro.zip
MD5:
SHA256:
3960WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb3960.2539\Remcos v4.9.3 Pro.exe
MD5:
SHA256:
3720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9430F1AFA8A7B223876A48A9BD0AF49E_51C62C590BD0DE4E3BDCA66FB8E819EAbinary
MD5:F25C8713E13A4B9AD8C06A533EB9B5BA
SHA256:15FD801E5F4AA17F8171423F98F6E571815E5038FE062D1C84D6D74145369C89
3720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562binary
MD5:7CEE9B9A5C755762AEFCF010B23EA104
SHA256:43134E740D828B663DC4AEB7D2D446648F6633E08BA50CEA76E2670BA71B81EB
3720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\84AFE219AEC53B0C9251F5E19EF019BD_2C9D5E6D83DF507CBE6C15521D5D3562der
MD5:5A6508503C3D0D836B9D7D3F63B6EAA8
SHA256:185DC72407B6908E6BC9CD9BE64A92C113A112F0ACC92FE28825C737B6CD9E3A
3720iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MFAQUS6V\Remcos-v4.9.3-Pro[1].zipcompressed
MD5:4097D31FE332F688E20724CEB448334D
SHA256:35A3A6E953060BF5464C1DBD510B871DDE9B9015889CC5753D72AEE4D08DDEBF
3720iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:69962D0BA72D47AD35D0CDA71268A596
SHA256:3183C88FE7E67FCBE78C722AFE4D59E7EEC3011589F2EFD93D5EF477164FAB53
3656iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\urlblockindex[1].binbinary
MD5:FA518E3DFAE8CA3A0E495460FD60C791
SHA256:775853600060162C4B4E5F883F9FD5A278E61C471B3EE1826396B6D129499AA7
3656iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776der
MD5:AE042CBB1AC8C1449D76ACCECF94DD81
SHA256:B186D44EF30080B9D84D7DD60AEE0B63265D192602AE4C5AE33D5048F787D653
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
24
TCP/UDP connections
66
DNS requests
105
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3720
iexplore.exe
GET
304
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?927e0d673a39dd41
unknown
unknown
2724
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
unknown
text
90 b
unknown
2724
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2724
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
2724
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
unknown
text
8 b
unknown
2724
firefox.exe
POST
142.250.186.67:80
http://ocsp.pki.goog/gts1c3
unknown
unknown
2724
firefox.exe
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
POST
200
142.250.186.67:80
http://ocsp.pki.goog/gts1c3
unknown
binary
471 b
unknown
POST
200
23.53.40.161:80
http://r3.o.lencr.org/
unknown
binary
503 b
unknown
3720
iexplore.exe
GET
304
46.228.146.128:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d362edf7b65e9a48
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3720
iexplore.exe
192.124.249.19:443
SUCURI-SEC
US
unknown
3720
iexplore.exe
46.228.146.128:80
ctldl.windowsupdate.com
LLNW
US
unknown
3720
iexplore.exe
192.124.249.22:80
ocsp.starfieldtech.com
SUCURI-SEC
US
unknown
3656
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
3656
iexplore.exe
46.228.146.128:80
ctldl.windowsupdate.com
LLNW
US
unknown
3656
iexplore.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
breakingsecurity.net
  • 34.120.158.37
whitelisted
ctldl.windowsupdate.com
  • 46.228.146.128
  • 46.228.146.0
  • 93.184.221.240
whitelisted
ocsp.starfieldtech.com
  • 192.124.249.22
  • 192.124.249.36
  • 192.124.249.24
  • 192.124.249.41
  • 192.124.249.23
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ieonline.microsoft.com
  • 204.79.197.200
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
www.msn.com
  • 131.253.33.203
whitelisted
p4-preview.runhosting.com
  • 185.176.40.57
malicious

Threats

No threats detected
No debug info