MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 121d2d6690530e93ca3953ec815f19ecfd771f8a6c56196d56bf458049b80231. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 121d2d6690530e93ca3953ec815f19ecfd771f8a6c56196d56bf458049b80231
SHA3-384 hash: 51c13f2d33a8719280663bd3d1269d31968ae97d75a257891c449cd561c195235c9a901482763ea838ede8cbc3d6e8c8
SHA1 hash: 86eebaff3e5b196f534bf1d25cc0c1828c585d70
MD5 hash: 0cdcf84cf2d9aee80555150ab67b9912
humanhash: bravo-island-fruit-video
File name:121d2d6690530e93ca3953ec815f19ecfd771f8a6c56196d56bf458049b80231
Download: download sample
File size:6'422'863 bytes
First seen:2020-06-16 09:24:38 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 676f4bc1db7fb9f072b157186a10179e (1'400 x AveMariaRAT, 37 x Riskware.Generic, 2 x njrat)
ssdeep 49152:ATU7AAmw4gxeOw46fUbNecCCFbNecFTU7AAmw4gxeOw46fUbNecCCFbNecq:ATU7d9xZw46G8q8mTU7d9xZw46G8q8x
Threatray 1'470 similar samples on MalwareBazaar
TLSH 2656AED2B5296027F521E572E00FB5138A8E2C1E724247DF773ABA1980EF95AD5D230F
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-06-13 00:41:21 UTC
File Type:
PE (Exe)
Extracted files:
25
AV detection:
44 of 48 (91.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Drops file in Windows directory
Suspicious use of SetThreadContext
Adds Run entry to start application
Drops startup file
Loads dropped DLL
Modifies the visibility of hidden or system files
Executes dropped EXE
Modifies Installed Components in the registry
Modifies WinLogon for persistence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments