Statik Analiz — RemcosRAT | YÜKSEK | CVSS: 7.5

Dosya

SHA256902f94d7819fa6a65e9ba1d491e8fc7cb3d2bcb15ae1e4a89a065223d815f9f8
MD57226fb1c7386c342d188c0b9467f7bc5
Dosya902f94d7819fa6a65e9ba1d491e8fc7cb3d2bcb15ae1e4a89a065223d815f9f8.exe
Boyut1,242,624 byte
TürPE32 executable for MS Windows 6.00 (GUI), Intel i386 Mono/.Net assembly, 3 sections
Stringler2,446

Bölümler

AdEntropi
.text7.94
.rsrc3.7
.reloc0.08

Import Tablosu

  • mscoree.dll

IOC

SHA256902f94d7819fa6a65e9ba1d491e8fc7cb3d2bcb15ae1e4a89a065223d815f9f8
MD57226fb1c7386c342d188c0b9467f7bc5
IP16.10.0.0, 16.0.0.0, 1.0.0.0, 4.0.0.0

RemcosRAT — Malware Profile

RemcosRAT - BreakingSecurity.net tarafindan lisansli satilan uzaktan erisim araci. Mesbru pentesting araci olarak satilsa da kriminal aktörler tarafindan yaygin kullanilir. Process hollowing, keylogger, clipboard/audio/screenshot izleme, Chrome kimlik bilgisi hirsizligi, UAC bypass, TLS 1.3 sifreli C2.

Malware Type
RAT
Programming Language
C++
C2 Protocol
TCP/RC4
Target Systems
Windows
Also Known As (AKA)
Remcos, Breaking-Security

Technical Details

TCP port 2404 (varsayilan), RC4 veya XOR sifreleme, C++ ile gelistirilmis, PE injection, UAC bypass (CMSTPLUA), AMSI bypass, Anti-debug (GetTickCount/RDTSC), DGA destekli C2, Keylogger, Screenshot, Audio

Attribution / Threat Actor

Breaking Security firmasinin isvicre tabanli olmasi nedeniyle ilk gelistirme AB'de gerceklestirilmistir; ancak surekli dunya genelinde siber suclu topluluklari tarafindan kullanilmaktadir.

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (4 indicators)

IOC — RemcosRAT
# IP 16.10.0.0 # IP 16.0.0.0 # IP 1.0.0.0 # IP 4.0.0.0
TypeValueNote
ip 16.10.0.0 C2 aday
ip 16.0.0.0 C2 aday
ip 1.0.0.0 C2 aday
ip 4.0.0.0 C2 aday

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
breakingsecurity.net domain — TCP active —
system.io domain — TCP active —
breakingsecurity.net domain — TCP active —
system.io domain — TCP active —
breakingsecurity.net domain — TCP active —
paint.net domain — TCP active —
americanshippingline.com domain — TCP active —
purl.org domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
RemcosRATmalwarestatik-analizIOC