Concrete signature match: Backdoor - Provides unauthorized remote access for 32-bit Windows platform, family Remcos
This detection identifies the Remcos Remote Access Trojan (RAT), a backdoor that gives an attacker complete control over the infected system. The malware establishes persistence by copying itself to the AppData folder and adding a registry run key, then connects to a command-and-control server (64.227.120.150) for remote operation.
No detailed analysis available from definition files.
c2edaac5f9a927708521a7a359a03045f43afaef0b970b3cf1bf9d6dd75134baf48b56e4f61e6ab518d100b332aacd7c21cc7a0f01b63b98ab445fa3fa6638e503a797a85e78a0c08c78f8ee804d8d2dfff5400adbf65678beb5066761b1d2a52001f036444665272ea360854d4dfd7d0798d6a717d3a1806e856b7d48531ce8820e9bde246981cf653616887b1b6a5fba61bacb3e1d8b30ca9f2c7af54a573dIsolate the host from the network immediately. Use antivirus to remove the threat, then manually verify the removal of the file in `%APPDATA%\remcos\` and the associated registry run key. Reset all user credentials accessed from this machine and block the C2 IP (64.227.120.150) at the firewall.