2021-01-06 (WEDNESDAY) - REMCOS RAT INFECTION
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES
- 2021-01-06-IOCs-for-Recmos-RAT-activity.txt.zip 1.1 kB (1,069 bytes)
- 2021-01-06-IOCs-for-Recmos-RAT-activity.txt (1,767 bytes)
- 2021-01-06-Remcos-RAT-infection.pcap.zip 506 kB (506,121 bytes)
- 2021-01-06-Remcos-RAT-infection.pcap (895,221 bytes)
- 2021-01-06-Remcos-RAT-malware-and-artifacts.zip 523 kB (522,528 bytes)
- 2021-01-06-EXE-seen-during-Recmos-RAT-infection-process.bin (3,072 bytes)
- 2021-01-06-Remcos-RAT-installer-EXE.bin (738,248 bytes)
- 2021-01-06-XLS-spreadsheet-with-macros-for-Remcos-RAT.bin (34,816 bytes)
- 2021-01-06-persistent-Remcos-RAT-EXE.bin (131,072 bytes)
IMAGES
Shown above: Screenshot of Excel spreadsheet with macro for Remcos RAT. Click on the above picture for a higher-resolution image.
Shown above: Traffic from the infection filtered in Wireshark. Click on the above picture for a higher-resolution image.
Shown above: Windows registry update and persistent location for Remcos RAT. Click on the above picture for a higher-resolution image.
Click here to return to the main page.