2021-01-06 (WEDNESDAY) - REMCOS RAT INFECTION
ASSOCIATED FILES
- 2021-01-06-IOCs-for-Recmos-RAT-activity.txt.zip 1.1 kB (1,069 bytes)
- 2021-01-06-IOCs-for-Recmos-RAT-activity.txt (1,767 bytes)
- 2021-01-06-Remcos-RAT-infection.pcap.zip 506 kB (506,121 bytes)
- 2021-01-06-Remcos-RAT-infection.pcap (895,221 bytes)
- 2021-01-06-Remcos-RAT-malware-and-artifacts.zip 522 kB (521,960 bytes)
- 2021-01-06-EXE-seen-during-Recmos-RAT-infection-process.bin (3,072 bytes)
- 2021-01-06-Remcos-RAT-installer-EXE.bin (738,248 bytes)
- 2021-01-06-XLS-spreadsheet-with-macros-for-Remcos-RAT.bin (34,816 bytes)
- 2021-01-06-persistent-Remcos-RAT-EXE.bin (131,072 bytes)
NOTES:
- All zip archives on this site are password-protected with the standard password. If you don't know it, see the "about" page of this website.
IMAGES
Shown above: Screenshot of Excel spreadsheet with macro for Remcos RAT. Click on the above picture for a higher-resolution image.
Shown above: Traffic from the infection filtered in Wireshark. Click on the above picture for a higher-resolution image.
Shown above: Windows registry update and persistent location for Remcos RAT. Click on the above picture for a higher-resolution image.
Click here to return to the main page.