Statik Analiz — RemcosRAT | YÜKSEK | CVSS: 7.5

Dosya

SHA256b5cbdc55f9895f4167817318d73c3891a6d762759a32926e03cff8488b315417
MD56dfd4e4a99202b2b5cab0f367ef11da9
Dosyab5cbdc55f9895f4167817318d73c3891a6d762759a32926e03cff8488b315417.xls
Boyut669,696 byte
TürComposite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Name
Stringler1,616

IOC

SHA256b5cbdc55f9895f4167817318d73c3891a6d762759a32926e03cff8488b315417
MD56dfd4e4a99202b2b5cab0f367ef11da9
Domainpaint.net, americanshippingline.com, purl.org, adobe.com
BTC146A386CB769FA41A3939AC777FCD6F9
C2paint.net, americanshippingline.com, purl.org, adobe.com

RemcosRAT — Malware Profile

RemcosRAT - BreakingSecurity.net tarafindan lisansli satilan uzaktan erisim araci. Mesbru pentesting araci olarak satilsa da kriminal aktörler tarafindan yaygin kullanilir. Process hollowing, keylogger, clipboard/audio/screenshot izleme, Chrome kimlik bilgisi hirsizligi, UAC bypass, TLS 1.3 sifreli C2.

Malware Type
RAT
Programming Language
C++
C2 Protocol
TCP/RC4
Target Systems
Windows
Also Known As (AKA)
Remcos, Breaking-Security

Technical Details

TCP port 2404 (varsayilan), RC4 veya XOR sifreleme, C++ ile gelistirilmis, PE injection, UAC bypass (CMSTPLUA), AMSI bypass, Anti-debug (GetTickCount/RDTSC), DGA destekli C2, Keylogger, Screenshot, Audio

Attribution / Threat Actor

Breaking Security firmasinin isvicre tabanli olmasi nedeniyle ilk gelistirme AB'de gerceklestirilmistir; ancak surekli dunya genelinde siber suclu topluluklari tarafindan kullanilmaktadir.

Capabilities & Behavior

Uzaktan Erişim & Kontrol
Keylogger
Ekran Görüntüsü
Webcam Erişimi
Dosya Yönetimi
Süreç Yönetimi
Komut Yürütme
Kalıcılık Mekanizması

IOC List (5 indicators)

IOC — RemcosRAT
# 146A386CB769FA41A3939AC777FCD6F9 # DOMAIN paint.net # DOMAIN americanshippingline.com # DOMAIN purl.org # DOMAIN adobe.com
TypeValueNote
146A386CB769FA41A3939AC777FCD6F9 BTC
domain paint.net C2 domain
domain americanshippingline.com C2 domain
domain purl.org C2 domain
domain adobe.com C2 domain

C2 Servers (8 recorded servers for this family)

Address Type Port Protocol Status Country
breakingsecurity.net domain — TCP active —
system.io domain — TCP active —
breakingsecurity.net domain — TCP active —
system.io domain — TCP active —
breakingsecurity.net domain — TCP active —
paint.net domain — TCP active —
americanshippingline.com domain — TCP active —
purl.org domain — TCP active —

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
RemcosRATmalwarestatik-analizIOC