Remcos RAT
Remcos RAT, initially developed as a legitimate tool for remote computer control, has gained notoriety as a malware family due to its exploitation by hackers for unauthorized access to victims' devices since its inception on July 21, 2016. Despite its origins as professional software, it has been repurposed for malicious activities. It is available for purchase on the internet, making it a commercial product in the realm of cyber threats.
- Windows XP to Windows 11, both 32-64 bit, including Server editions.
Infection Vector
Remcos is frequently distributed through phishing attacks. It is often concealed within a deceptive ZIP file, pretending to be a PDF document related to an invoice or order. Another method involves the use of Microsoft Office documents with embedded malicious macros. When opened, these documents unpack and execute the Remcos malware, showcasing the versatility of tactics employed by attackers in disseminating this threat.
Identification
- C2 Communication
- 107[.]175.229[.]139[:]8087
- dksak[.]ddns[.]net[:]3835
- Behavior
- "http://geoplugin.net/json.gp"
- "C:\ProgramData\remcos\"
- Strings
- "remcos"
- "breakingsecurity.net"
- "Remcos restarted by watchdog!"
MITRE ATT&CK
- T1053 - Scheduled Task/Job
- T1056 - Keylogging
- T1113 - Screen Capture
- T1123 - Audio Capture
Evasion techniques
- Process Injection - Remcos includes a command that allows it to conceal its presence by injecting into a different process.
- Obfuscated Files or Information - Remcos employs RC4 encryption and base64 encoding techniques to obscure data, encompassing Registry entries and file paths.
IOC's
- Hash
- 16d59170db4782c9bba800a67dc79644
- ce569d3efa2fb1128f4d321287dd5dfa
- 925cc5d77586311bd5cefbb430d051e1
- a11bd4344a81f6a0fddce8735cef714d
- C2
- 107.175[.]229.139[:]8087
- cloudhost[.]myfirewall.org[:]9302
- grantadistciaret[.]com[:]3212
- 9.tcp.ngrok[.]io[:]22201
Comments
Post a Comment