General
-
Target
076a4a72c5285c9d30401f1c3f7d0c45.bin
-
Size
265KB
-
Sample
240705-bc7t1aycjn
-
MD5
6ab9eb9cb3241aee0ae378ba19182053
-
SHA1
6dedb35bd80107663f596fdc40700bd3ebb9d204
-
SHA256
0d1a70f426548e59a94c4244de64b1c9f33c3e0353d4cb456273d2171ca4af25
-
SHA512
cd01e2a081abe9c2120421c7325fe7f15bfdcc875e571610a89bf7672bf9674b299ff61e4e8fcbc31dd740be4e235fd50965d07df6453a209a6e05c99712a1d6
-
SSDEEP
6144:pcNujAqxfbZoLEtoSFIsM5whbAwh7YHGSX:cwAqhdoYdFIsMQbV7YbX
Behavioral task
behavioral1
Sample
0c286126eae5d8d419bac3830831dbcfd0deb2b375d21666de4eac3c9824f4a8.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
0c286126eae5d8d419bac3830831dbcfd0deb2b375d21666de4eac3c9824f4a8.exe
Resource
win10v2004-20240704-en
Malware Config
Extracted
remcos
FREE
191.101.130.177:6903
-
audio_folder
MicRecords
-
audio_record_time
5
-
connect_delay
0
-
connect_interval
1
-
copy_file
remcos.exe
-
copy_folder
Remcos
-
delete_file
false
-
hide_file
false
-
hide_keylog_file
false
-
install_flag
false
-
keylog_crypt
false
-
keylog_file
logs.dat
-
keylog_flag
false
-
keylog_folder
remcos
-
mouse_option
false
-
mutex
Rmc-6PAAVG
-
screenshot_crypt
false
-
screenshot_flag
false
-
screenshot_folder
Screenshots
-
screenshot_path
%AppData%
-
screenshot_time
10
-
take_screenshot_option
false
-
take_screenshot_time
5
Targets
-
-
Target
0c286126eae5d8d419bac3830831dbcfd0deb2b375d21666de4eac3c9824f4a8.exe
-
Size
483KB
-
MD5
076a4a72c5285c9d30401f1c3f7d0c45
-
SHA1
e1e0a55107a970883aaa0e111ae36a3f0d901f8a
-
SHA256
0c286126eae5d8d419bac3830831dbcfd0deb2b375d21666de4eac3c9824f4a8
-
SHA512
a7cbeba2ffc91119a22d98a282d7b992aa23c8ce34793c7e7642cd2056f2d75f3c8d9a8fa44773408482a4307d4991dfcc4c188e9bf28aedfcbf55c03e733ab4
-
SSDEEP
6144:6XIktXfM8Lv86r9uVWAa2je4Z5zl4hgDHQQs4NTQjoHFsAOZZDAXYcNl5Gv:6X7tPMK8ctGe4Dzl4h2QnuPs/ZDccv
Score1/10 -