Remcos RAT

 

 
Remcos RAT, initially developed as a legitimate tool for remote computer control, has gained notoriety as a malware family due to its exploitation by hackers for unauthorized access to victims' devices since its inception on July 21, 2016. Despite its origins as professional software, it has been repurposed for malicious activities. It is available for purchase on the internet, making it a commercial product in the realm of cyber threats.
 
Target OS 

  • Windows XP to Windows 11, both 32-64 bit, including Server editions.

Infection Vector

Remcos is frequently distributed through phishing attacks. It is often concealed within a deceptive ZIP file, pretending to be a PDF document related to an invoice or order. Another method involves the use of Microsoft Office documents with embedded malicious macros. When opened, these documents unpack and execute the Remcos malware, showcasing the versatility of tactics employed by attackers in disseminating this threat.

Identification

  • C2 Communication
    • 107[.]175.229[.]139[:]8087
    • dksak[.]ddns[.]net[:]3835
  • Behavior
    • "http://geoplugin.net/json.gp"
    • "C:\ProgramData\remcos\"
  • Strings
    • "remcos"
    • "breakingsecurity.net"
    • "Remcos restarted by watchdog!"

MITRE ATT&CK

  • T1053 - Scheduled Task/Job
  • T1056 - Keylogging
  • T1113 - Screen Capture
  • T1123 - Audio Capture

Evasion techniques

  • Process Injection  - Remcos includes a command that allows it to conceal its presence by injecting into a different process.
  • Obfuscated Files or Information - Remcos employs RC4 encryption and base64 encoding techniques to obscure data, encompassing Registry entries and file paths. 

IOC's

  • Hash 
    • 16d59170db4782c9bba800a67dc79644
    • ce569d3efa2fb1128f4d321287dd5dfa
    • 925cc5d77586311bd5cefbb430d051e1
    • a11bd4344a81f6a0fddce8735cef714d
  •  C2
    • 107.175[.]229.139[:]8087
    • cloudhost[.]myfirewall.org[:]9302
    • grantadistciaret[.]com[:]3212
    • 9.tcp.ngrok[.]io[:]22201
for more IOC

Comments