MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f03dc74c1726fac03fd3c9437f2be7105312b5c9fc55cb3eb88fed59570793f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: f03dc74c1726fac03fd3c9437f2be7105312b5c9fc55cb3eb88fed59570793f3
SHA3-384 hash: ed925cb6c26f9889f8b26ba392145fd2b3bd93211e5c2bfdbfa9ef380f8e6ab8310b7fe156efb866c3419b48246bb592
SHA1 hash: a9b6475217c385837e5b1db444c91b952b74a2f2
MD5 hash: c4dd4bc82a36181cd1bd78e9dfb36219
humanhash: fourteen-sierra-idaho-princess
File name:SOA Outstanding.zip
Download: download sample
Signature AveMariaRAT
File size:271'830 bytes
First seen:2020-08-05 15:35:50 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:pRpirqHjLmVHlz7Qf6H54EJ5+GdXkXxsiIGF8m538UgVXKh:pD7DiVHlHQf6HWEJ8GdXkSwv53tiKh
TLSH 60442373C2DB3D06C54D6862974590B5F1A5C3E0FF16EECCCAA3ED6629283AD441AE09
Reporter abuse_ch
Tags:AveMariaRAT RAT zip


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: asatelectricals.com
Sending IP: 80.85.157.189
From: finance@asatelectricals.com
Subject: SOA FOR PAYMENT PROCESSING
Attachment: SOA Outstanding.zip (contains "SOA Outstanding.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
66
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

zip f03dc74c1726fac03fd3c9437f2be7105312b5c9fc55cb3eb88fed59570793f3

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments