IOC Radar
TLP:WHITE6 IOCs

Remcos RAT New TTPS – Detection & Response

SI
Security Investigation
Published August 29, 2022Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE194.147.140.29falimore001.hopto.org178.237.33.50CAPABILITYQakBotRemcosVICTIMunknown
Adversary
Infrastructure(3)
Capability(2)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise6

TypeIndicatorConfidenceScoreFirst Seen
IP194.147.140.29
intel-blogmalwarenetwork
High
58
Jun 2, 26
MD58cea687c5c02c9b71303c53dc2641f03
file-hashintel-blogmalware
Medium
53
Jun 2, 26
Domainfalimore001.hopto.org
intel-blogmalwarenetwork
High
58
Jun 2, 26
MD56d25e04e66cccb61648f34728af7c2f2
file-hashintel-blogmalware
Medium
53
Jun 2, 26
IP178.237.33.50
intel-blogmalwarenetwork
High
58
Jun 2, 26
MD5f331c18c3f685d245d40911d3bd20519
file-hashintel-blogmalware
Medium
53
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph6 total IOCs
IPMD5Domain
MD53IP2Domain1Malware2REPORTRemcos RAT New TTPS – DeteQakBotRemcos
scroll to zoom · drag to pan · click IOC to open