Tracing Remcos RAT
ID: ec841221-71e3-52b5-9b0d-02bcd1817d9d
STIX ID: report--ec841221-71e3-52b5-9b0d-02bcd1817d9d
Feed Name: IntelInsights (Substack)
The report investigates a suspected Remcos RAT infection delivered via phishing (filetransfer.io), analyzes the sample’s communications (e.g., 185.29.10.213:63650), and pivots across ASN 60567 and SSH fingerprint/port combinations to identify related infrastructure. It presents IP IOCs with mixed confidence—moderate for broader infrastructure leads and high for a small set of malware-communicating IPs—while cautioning that attribution to Remcos is not definitive due to overlapping use by varied threat activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
