Remcos RAT Distributed as UUEncoding (UUE) File
ID: db72964b-d32b-5a89-b551-4765f4f74851
STIX ID: report--db72964b-d32b-5a89-b551-4765f4f74851
Feed Name: ASEC
Threat Score
AhnLab ASEC identified a phishing campaign delivering Remcos RAT via UUE-encoded VBS attachments (distributed in Power Archiver archives). The VBS drops obfuscated PowerShell scripts that download additional binaries from http://194.59.30.90, inject shellcode into wab.exe, add registry persistence, and execute Remcos which gathers system info and keylogs before exfiltration to duckdns C2 domains; the report includes IPs, domains, and MD5 hashes as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
