Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Remcos, RemcosRAT | Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity. |
|
|
AV Detection |
|
---|
Source: |
Malware Configuration Extractor: |
Source: |
Virustotal: |
Perma Link |
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Source: |
Avira: |
Source: |
URL Reputation: |
||
Source: |
URL Reputation: |
||
Source: |
URL Reputation: |
||
Source: |
Avira URL Cloud: |
Source: |
Virustotal: |
Perma Link | ||
Source: |
Virustotal: |
Perma Link |
Source: |
Joe Sandbox ML: |
Source: |
Code function: |
0_2_00433785 |
Source: |
Binary or memory string: |
memstr_e80f468d-2 |
Exploits |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Privilege Escalation |
|
---|
Source: |
Code function: |
0_2_004074FD |
Source: |
Static PE information: |
Source: |
Code function: |
0_2_0041C1DF | |
Source: |
Code function: |
0_2_00409253 | |
Source: |
Code function: |
0_2_0040C29B | |
Source: |
Code function: |
0_2_00409665 | |
Source: |
Code function: |
0_2_0040880C | |
Source: |
Code function: |
0_2_0040783C | |
Source: |
Code function: |
0_2_00419A43 | |
Source: |
Code function: |
0_2_0040BA7E | |
Source: |
Code function: |
0_2_0040BC85 |
Source: |
Code function: |
0_2_00407C97 |
Networking |
|
---|
Source: |
TCP traffic: |
Source: |
URLs: |
Source: |
ASN Name: |
Source: |
HTTP traffic detected: |
Source: |
IP Address: |
Source: |
TCP traffic: |
Source: |
UDP traffic detected without corresponding DNS query: |
||
Source: |
UDP traffic detected without corresponding DNS query: |
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
||
Source: |
String found in binary or memory: |
Source: |
DNS traffic detected: |
Source: |
Code function: |
0_2_0041B2CE |
Source: |
HTTP traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
---|
Source: |
Code function: |
0_2_0040A2B8 |
Source: |
Code function: |
0_2_0041680F |
Source: |
Code function: |
0_2_0040B65C |
Source: |
Code function: |
0_2_0040A3E0 |
Source: |
Code function: |
0_2_0040B65C |
E-Banking Fraud |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Spam, unwanted Advertisements and Ransom Demands |
|
---|
Source: |
Code function: |
0_2_0041C930 |
System Summary |
|
---|
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
Source: |
Static PE information: |
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
||
Source: |
Matched rule: |
Source: |
Code function: |
0_2_00416702 |
Source: |
Code function: |
0_2_0041F048 | |
Source: |
Code function: |
0_2_0043E00C | |
Source: |
Code function: |
0_2_0045409A | |
Source: |
Code function: |
0_2_004380A8 | |
Source: |
Code function: |
0_2_00446130 | |
Source: |
Code function: |
0_2_0045326C | |
Source: |
Code function: |
0_2_0043E23B | |
Source: |
Code function: |
0_2_004272EB | |
Source: |
Code function: |
0_2_00437426 | |
Source: |
Code function: |
0_2_0043E498 | |
Source: |
Code function: |
0_2_004386B0 | |
Source: |
Code function: |
0_2_0043783E | |
Source: |
Code function: |
0_2_0044D889 | |
Source: |
Code function: |
0_2_00433894 | |
Source: |
Code function: |
0_2_00427994 | |
Source: |
Code function: |
0_2_00427AFD | |
Source: |
Code function: |
0_2_0041DAB0 | |
Source: |
Code function: |
0_2_00437C73 | |
Source: |
Code function: |
0_2_00426D5C | |
Source: |
Code function: |
0_2_0043DDDD | |
Source: |
Code function: |
0_2_00435DA1 | |
Source: |
Code function: |
0_2_00413F18 | |
Source: |
Code function: |
0_2_00436F2A |
Source: |
Code function: |
0_2_00413220 | |
Source: |
Code function: |
0_2_0041BA57 | |
Source: |
Code function: |
0_2_0041BA83 |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Virustotal: |
Source: |
Static PE information: |
Source: |
Key opened: |
Jump to behavior |
Source: |
Process created: |
|||
Source: |
Process created: |
|||
Source: |
Process created: |
Jump to behavior |
Source: |
Key value queried: |
Jump to behavior |
Source: |
Code function: |
0_2_004178A0 |
Source: |
File created: |
Jump to behavior |
Source: |
File created: |
Jump to behavior |
Source: |
Classification label: |
Source: |
File read: |
Jump to behavior |
Source: |
Code function: |
0_2_0041A998 |
Source: |
Code function: |
0_2_0040F3C2 |
Source: |
Mutant created: |
Source: |
Code function: |
0_2_0041B3F6 |
Source: |
Process created: |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_0040E913 | |
Source: |
Command line argument: |
0_2_004571B0 |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Static PE information: |
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
||
Source: |
Static PE information: |
Source: |
Code function: |
0_2_00457059 | |
Source: |
Code function: |
0_2_00457986 | |
Source: |
Code function: |
0_2_00434DC9 |
Source: |
Code function: |
0_2_0041CA9E |
Source: |
Code function: |
0_2_00406EB0 |
Source: |
Code function: |
0_2_0041A998 |
Hooking and other Techniques for Hiding and Protection |
|
---|
Source: |
File deleted: |
Jump to behavior |
Source: |
Code function: |
0_2_0041CA9E |
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior | ||
Source: |
Process information set: |
Jump to behavior |
Malware Analysis System Evasion |
|
---|
Source: |
Code function: |
0_2_0040F6F5 |
Source: |
Code function: |
0_2_0041A696 |
Source: |
Window found: |
Jump to behavior |
Source: |
Code function: |
0_2_0041C1DF | |
Source: |
Code function: |
0_2_00409253 | |
Source: |
Code function: |
0_2_0040C29B | |
Source: |
Code function: |
0_2_00409665 | |
Source: |
Code function: |
0_2_0040880C | |
Source: |
Code function: |
0_2_0040783C | |
Source: |
Code function: |
0_2_00419A43 | |
Source: |
Code function: |
0_2_0040BA7E | |
Source: |
Code function: |
0_2_0040BC85 |
Source: |
Code function: |
0_2_00407C97 |
Source: |
API call chain: |
Source: |
Binary or memory string: |
||
Source: |
Binary or memory string: |
Source: |
Code function: |
0_2_00434947 |
Source: |
Code function: |
0_2_0041CA9E |
Source: |
Code function: |
0_2_0044FA8E |
Source: |
Code function: |
0_2_00443214 |
Source: |
Code function: |
0_2_00434947 | |
Source: |
Code function: |
0_2_0043BA62 | |
Source: |
Code function: |
0_2_00434A95 | |
Source: |
Code function: |
0_2_00434F3C |
Source: |
Code function: |
0_2_00412065 |
Source: |
Process created: |
Jump to behavior |
Source: |
Code function: |
0_2_00419575 |
Source: |
Binary or memory string: |
Source: |
Code function: |
0_2_0040F81F | |
Source: |
Code function: |
0_2_00452004 | |
Source: |
Code function: |
0_2_00452254 | |
Source: |
Code function: |
0_2_004482C4 | |
Source: |
Code function: |
0_2_0045237D | |
Source: |
Code function: |
0_2_00452484 | |
Source: |
Code function: |
0_2_00452551 | |
Source: |
Code function: |
0_2_004487AD | |
Source: |
Code function: |
0_2_00451C19 | |
Source: |
Code function: |
0_2_00451EDC | |
Source: |
Code function: |
0_2_00451E91 | |
Source: |
Code function: |
0_2_00451F77 |
Source: |
Code function: |
0_2_00434BBD |
Source: |
Key value queried: |
Jump to behavior |
Source: |
Code function: |
0_2_0041B74D |
Source: |
Code function: |
0_2_0044926D |
Source: |
Code function: |
0_2_0041B55B |
Stealing of Sensitive Information |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Source: |
Code function: |
0_2_0040BA7E | |
Source: |
Code function: |
0_2_0040BA7E |
Source: |
Code function: |
0_2_0040B960 |
Remote Access Functionality |
|
---|
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
||
Source: |
File source: |
Source: |
Code function: |
0_2_0040569A |