MALICIOUS — a05e47692520185c1d3b5b0bb72b6a4b954064d2e28af22c5dad24fb2b924743.bin
MALICIOUS — a05e47692520185c1d3b5b0bb72b6a4b954064d2e28af22c5dad24fb2b924743.bin is a script sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (92/100), attributed to the RemcosRATt family. 3 of 23 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a05e47692520185c1d3b5b0bb72b6a4b954064d2e28af22c5dad24fb2b924743 - SHA-1:
38dbd2460eb0886bb773cba229ec479a0b7d6dec - MD5:
eb68387c3cddac70afe315bbb18d85c4 - ssdeep:
98304:MCzJ0S1W2+Hy8y1ZNe7x5SF2OqlADbxja2RRN8/hn6aDkVc1rJSd:30g7+S81VLOqlIbVau8JPScHSd - TLSH:
T1266329F3438B33DEEDCE2C41D7E5AEB6842CE2AB1172D429420E42792D94DC47A14967 - Submitted as: a05e47692520185c1d3b5b0bb72b6a4b954064d2e28af22c5dad24fb2b924743.bin
- File type: script · Size: 5031255 bytes
- Verdict: malicious (92/100) · Family: RemcosRATt
Detections (3 of 23 engines)
- Microsoft Defender: Trojan:JS/RemcosRATt.SB!MTB
- Emsisoft (Emergency Kit): JS:Trojan.Cryxos.16557
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 92/100 is the fusion of 5 weighted signals:
- Microsoft Defender flagged Trojan:JS/RemcosRATt.SB!MTB (rule
Trojan:JS/RemcosRATt.SB!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged JS:Trojan.Cryxos.16557 (rule
JS:Trojan.Cryxos.16557) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Script.Generic (rule
HEUR:Trojan.Script.Generic) - engine signal, weight 0.55, confidence 0.85 - Obfuscated javascript script: dynamic-exec (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 4 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
Dynamic analysis (linux)
849 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- WORKGROUP
- 250.255.255.239.in-addr.arpa
- ntp.ubuntu.com
- desktop-hsgcbep
- 10.240.0.255
- 224.0.0.251
- ff02::fb
- ff02::1:3
- 224.0.0.252
- 10.240.0.1
- ff02::16
- 20.184.175.9 US · San Jose · AS8075 Microsoft Corporation
- 91.189.91.157
- 74.178.240.61 NL · Amsterdam · AS8075 Microsoft Corporation
- ff02::2
- ff02::1
- ff02::1:ff4c:1d1d
- ff02::1:ff12:3456
- ff02::1:2
- 255.255.255.255
Dropped files
- tmp_tmp.pPDor4vExZ -
3af452d01ff9e900c9fbe457a0ad034b3eb6472c9d745be406fe9cb2aa790c32
Embedded IP addresses
- 20.184.175.9
- 74.178.240.61
More RemcosRATt samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report