2021-01-06 (WEDNESDAY) - REMCOS RAT INFECTION

NOTICE:

ASSOCIATED FILES

  • 2021-01-06-IOCs-for-Recmos-RAT-activity.txt   (1,767 bytes)
  • 2021-01-06-Remcos-RAT-infection.pcap   (895,221 bytes)
  • 2021-01-06-EXE-seen-during-Recmos-RAT-infection-process.bin   (3,072 bytes)
  • 2021-01-06-Remcos-RAT-installer-EXE.bin   (738,248 bytes)
  • 2021-01-06-XLS-spreadsheet-with-macros-for-Remcos-RAT.bin   (34,816 bytes)
  • 2021-01-06-persistent-Remcos-RAT-EXE.bin   (131,072 bytes)

 

IMAGES


Shown above:  Screenshot of Excel spreadsheet with macro for Remcos RAT.  Click on the above picture for a higher-resolution image.

 


Shown above:  Traffic from the infection filtered in Wireshark.  Click on the above picture for a higher-resolution image.

 


Shown above:  Windows registry update and persistent location for Remcos RAT.  Click on the above picture for a higher-resolution image.

 

Click here to return to the main page.