Threat Database Trojans Trojan.Remcos.AM

Trojan.Remcos.AM

By CagedTech in Trojans

Analysis Report

General information

Family Name: Trojan.Remcos.AM
Signature status: Hash Mismatch

Known Samples

MD5: e71a1228a890fd844d6ca149d214f328
SHA1: d3c695d67cfe4ba2f9ee9fb39c1b4e670d86034c
File Size: 5.42 MB, 5415800 bytes
MD5: b53e264c6748ad4e9ca9f24ac6ebb2c6
SHA1: 9730e4b9ff884fa6cb0fbf657abbfede8f8083d8
SHA256: 24FECD70045631D09AF99D2B411936C0138CCEB538956423FB75F66F8245A92F
File Size: 211.46 KB, 211456 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments LunaTranslator v7.23
Company Name ASUSTeK COMPUTER INC.
File Description LunaTranslator
File Version
  • 10.0.22621.31278
  • 7.23.1.0
Internal Name
  • CardReader_DCH_Realtek_Z_V10.0.22621.31278_33305.exe
  • LunaTranslator
Legal Copyright
  • HIllya51 (C) 2025
  • © ASUSTeK COMPUTER INC. All rights reserved.
Original Filename
  • CardReader_DCH_Realtek_Z_V10.0.22621.31278_33305.exe
  • LunaTranslator
Product Name
  • LunaTranslator
  • Realtek Card Reader Driver
Product Version
  • 10.0.22621.31278
  • 7.23.1.0

Digital Signatures

Signer Root Status
ASUSTeK COMPUTER INC. DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Hash Mismatch

File Traits

  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 708
Potentially Malicious Blocks: 72
Whitelisted Blocks: 593
Unknown Blocks: 43

Visual Map

0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 0 0 0 ? 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 ? 0 0 0 0 0 x 0 0 0 0 ? x x 0 0 0 0 0 0 ? 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 ? ? x ? 0 0 0 0 0 0 0 0 0 0 x x 0 x x x x x 0 0 x ? x x x x ? x x x x x 0 0 0 0 0 ? ? x ? ? ? x ? ? ? ? x x x 0 ? x x 0 ? ? 0 ? 0 0 0 ? 0 0 ? ? ? ? ? 0 ? 0 ? ? 0 0 0 0 0 x 0 ? x ? x ? x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 1 3 1 0 1 0 0 0 0 2 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 x x x 0 x x 0 0 0 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x 0 x 0 x x 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 1 1 0 0 x 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Farfli.BZ
  • Gamehack.QAB
  • Kryptik.BBJ
  • Kryptik.BBL
  • Remcos.AM
Show More
  • Rhadamanthys.B

Trending

Most Viewed

Loading...