Fileless Remcos RAT Malware Delivery - ASEC BLOG
Common Information
Type Value
UUID 68494b19-9191-4825-bd27-007ea4393036
Fingerprint 8c6519850daf0a0f
Analysis status DONE
Considered CTI value 2
Text language
Published July 29, 2021, 9 a.m.
Added to db Sept. 11, 2022, 4:59 p.m.
Last updated Nov. 18, 2024, 11:18 p.m.
Headline Fileless Remcos RAT Malware Delivery
Title Fileless Remcos RAT Malware Delivery - ASEC BLOG
Detected Hints/Tags/Attributes 39/2/18
Source URLs
Attributes
Details Type #Events CTI Value
Details Domain 708
google.com
Details Domain 1
vendorcreditglobal.online
Details Domain 1
twistednerd.dvrlists.com
Details File 149
msbuild.exe
Details File 1
fud.js
Details File 2130
cmd.exe
Details File 1212
powershell.exe
Details File 1
dino.jpg
Details File 27
agent.c4
Details md5 1
d2a77c2544cc8621d1aa94712f04b8f2
Details md5 1
c140a58ffaf225f718f458f7f3d5fb0c
Details md5 1
60a903c61969620e47d53a73834ab687
Details md5 1
5f26df061368bc395b87d693afb35990
Details md5 1
0006e15486d33e1e6e6a8731e5880612
Details IPv4 1
192.227.158.111
Details Url 1
http://192.227.158.111/fud.js
Details Url 1
http://vendorcreditglobal.online/file/dino.jpg
Details Windows Registry Key 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\lol