Summary: 2025/04/29 00:23
First reported date: 2016/08/05
Inquiry period : 2025/04/22 00:23 ~ 2025/04/29 00:23 (7 days), 3 search results
전 기간대비 -233% 낮은 트렌드를 보이고 있습니다.
악성코드 유형 FormBook 도 새롭게 확인됩니다.
기타 neconyd IoC VBScript httpstcoPoOiqUwJjt VBS 신규 키워드도 확인됩니다.
Remcos is a RAT type malware that attackers use to perform actions on infected machines remotely. This malware is extremely actively caped up to date with updates coming out almost every single month.
참고로 동일한 그룹의 악성코드 타입은 Remcos njRAT QuasarRAT 등 112개 종이 확인됩니다.
Trend graph by period
Related keyword cloud
Top 100# | Trend | Count | Comparison |
---|---|---|---|
1 | Remcos | 3 | ▼ -7 (-233%) |
2 | NetWireRC | 2 | ▼ -5 (-250%) |
3 | AsyncRAT | 1 | - 0 (0%) |
4 | last | 1 | - 0 (0%) |
5 | Top | 1 | - 0 (0%) |
6 | AgentTesla | 1 | - 0 (0%) |
7 | FormBook | 1 | ▲ new |
8 | Amadey | 1 | - 0 (0%) |
9 | snake | 1 | - 0 (0%) |
10 | neconyd | 1 | ▲ new |
11 | Tofsee | 1 | - 0 (0%) |
12 | XWorm | 1 | - 0 (0%) |
13 | IoC | 1 | ▲ new |
14 | Lumma | 1 | - 0 (0%) |
15 | VBScript | 1 | ▲ new |
16 | httpstcoPoOiqUwJjt | 1 | ▲ new |
17 | abusech | 1 | - 0 (0%) |
18 | VBS | 1 | ▲ new |
19 | Low | 1 | - 0 (0%) |
20 | RemcosRAT | 1 | - 0 (0%) |
21 | Advertising | 1 | ▼ -1 (-100%) |
Special keyword group
Top 5
Malware Type
This is the type of malware that is becoming an issue.
Keyword | Average | Label |
---|---|---|
Remcos |
|
3 (25%) |
NetWireRC |
|
2 (16.7%) |
AsyncRAT |
|
1 (8.3%) |
AgentTesla |
|
1 (8.3%) |
FormBook |
|
1 (8.3%) |

Attacker & Actors
The status of the attacker or attack group being issued.
No data.

Technique
This is an attack technique that is becoming an issue.
No data.

Country & Company
This is a country or company that is an issue.
No data.
Malware Family
Top 5
A malware family is a group of applications with similar attack techniques.
In this trend, it is classified into Ransomware, Stealer, RAT or Backdoor, Loader, Botnet, Cryptocurrency Miner.
Threat info
Last 5SNS
(Total : 3)Remcos NetWireRC AsyncRAT AgentTesla FormBook Amadey XWorm IoC Lumma VBScript VBS RemcosRAT Advertising
News
(Total : 0)No data.
Additional information
No | Title | Date |
---|---|---|
1 | Employee monitoring app exposes users, leaks 21+ million screenshots - Malware.News | 2025.04.28 |
2 | Introducing XSIAM 3.0 - Malware.News | 2025.04.28 |
3 | Deploy Bravely with Prisma AIRS - Malware.News | 2025.04.28 |
4 | 2025 Cyber Resilience Research Discovers Speed of AI Advancing Emerging Attack Types - Malware.News | 2025.04.28 |
5 | Intel CEO Targets Change in Corporate Culture to Shape Up - Bloomberg Technology | 2025.04.28 |
View only the last 5 |
No | Title | Date |
---|---|---|
1 | Multi-Stage Malware Attack Uses .JSE and PowerShell to Deploy Agent Tesla and XLoader - The Hacker News | 2025.04.18 |
2 | How MSSP Expertware Uses ANY.RUN’s Interactive Sandbox for Faster Threat Analysis - Malware.News | 2025.04.08 |
3 | Threat actors leverage tax season to deploy tax-themed phishing campaigns - Microsoft Security... | 2025.04.04 |
4 | Remcos RAT Malware Disguised as Major Carrier’s Waybill - Malware.News | 2025.04.02 |
5 | Russia-Linked Gamaredon Uses Troop-Related Lures to Deploy Remcos RAT in Ukraine - The Hacker News | 2025.03.31 |
View only the last 5 |
No | Category | URL | CC | ASN Co | Date |
---|---|---|---|---|---|
1 | c2 | http://www.sangrodrinkinbottleporto.xyz/ | 2025.04.21 | ||
2 | c2 | http://160.30.192.52:2404/ | 2025.04.14 | ||
3 | c2 | http://001remsw.ydns.eu/ | RO ![]() | Tennet Telecom Srl | 2025.04.11 |
4 | c2 | http://remsw.ydns.eu/ | 2025.04.11 | ||
5 | c2 | http://103.28.89.34:10101/ | HK ![]() | Amarutu Technology Ltd | 2025.03.31 |
View only the last 5 |
No | URL | CC | ASN Co | Reporter | Date |
---|---|---|---|---|---|
1 | https://paste.ee/r/tFMXEhUq/0 remcos | DaveLikesMalwre | 2025.04.10 | ||
2 | https://bitbucket.org/jorge2514/george/downloads/sosteff2025.txt base64 bitbucket Encoded remcos RemcosRAT rev-base64-loader | US ![]() | ATLASSIAN PTY LTD | DaveLikesMalwre | 2025.04.10 |
3 | http://62.60.226.112/file/3601_2042.exe remcos | IR ![]() | ASLINE LIMITED | skocherhan | 2025.02.28 |
4 | https://raw.githubusercontent.com/Oscarito20222/diciembre/refs/heads/main/sena.exe remcos RemcosRAT | US ![]() | FASTLY | skocherhan | 2025.02.28 |
5 | https://github.com/Oscarito20222/diciembre/raw/refs/heads/main/sena.exe github remcos RemcosRAT | US ![]() | MICROSOFT-CORP-MSN-AS-BLOCK | skocherhan | 2025.02.28 |
View only the last 5 |