MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0eedca79e7b45750f378eac0de93c7e1470d3eaf69fff59fc6bf177bc975b02c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 0eedca79e7b45750f378eac0de93c7e1470d3eaf69fff59fc6bf177bc975b02c
SHA3-384 hash: 0b6ef37be2f4c4c81a069651822d14014e7fb4595b7a6d30350d35a87c8590edcf8f29383d4ec2a26553a9277fb90ef3
SHA1 hash: 8758ba31bba4b1144150e9abd2e13aae71179795
MD5 hash: 4b90f4dfeaf1cb1e3db2a456b174a60f
humanhash: alpha-skylark-coffee-double
File name:New supplier Inquiry and PO 208202850_ DOC.uu
Download: download sample
Signature AveMariaRAT
File size:407'996 bytes
First seen:2020-08-27 05:40:24 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:WEIg5muRa3gY7qKhcX2AqMd/4DZBUDOiYqrXRXf9HY4RrMAHSU1ugZhEm:hIgMga3TrNkN4ZBCYgX5bMAH/JZ
TLSH C28423173C073A9035AA067D6BBD897257D35E7EA384D732CAEB1C12A0EF41825E416A
Reporter abuse_ch
Tags:AveMariaRAT RAT uu


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: smtp.aonbd.net
Sending IP: 117.58.240.41
From: Purchase Vertex Safety A.S <purchase.vertexsafety.com@protonmail.com>
Reply-To: Purchase Vertex Safety A.S <purchase.vertexsafety.com@protonmail.com>
Subject: Re: New Supplier Inquiry Vertex Instanbul Safety/Equipment/PO208202.
Attachment: New supplier Inquiry and PO 208202850_ DOC.uu (contains "New supplier Inquiry and PO 208202850_ DOC.exe")

AveMariaRAT C2:
divy.nerdpol.ovh:5200

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar 0eedca79e7b45750f378eac0de93c7e1470d3eaf69fff59fc6bf177bc975b02c

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments