MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1bb377e6413d2aba9a88cea30057245d46780b96fa5c79d3b0333dd6306d7722. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 1bb377e6413d2aba9a88cea30057245d46780b96fa5c79d3b0333dd6306d7722
SHA3-384 hash: e9da081df8a00eeb1989a5915db1055402edc87810300507a172283b4b0f4a4e1ffd0ae1e88edc7b13330b5188d05de8
SHA1 hash: 0b45adeaf81f7d7d1379880c2326293801cdfec2
MD5 hash: 247b71730c16aaccf778a10420ad39de
humanhash: stream-fruit-pip-hydrogen
File name:Guqcufv_Signed_.img
Download: download sample
Signature AveMariaRAT
File size:1'769'472 bytes
First seen:2020-07-13 12:01:28 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 24576:hEWNeUebPnGhlh40zI+N//y8QMvMMl8XZf1CDRX1/4LsD+zVxuTB1:KXVnx3O8ouLsD7r
TLSH 6F85AF72B1E11AF6C113093D7D1E72A95A27FE511FAAEE826FF91D0C8D66142383418F
Reporter abuse_ch
Tags:AveMariaRAT img


Avatar
abuse_ch
Malspam distributing unidentified malware:

HELO: smtp109.iad3a.emailsrvr.com
Sending IP: 173.203.187.109
From: Fixauto Inc <dave.schlemko@fixauto.com>
Reply-To: dave.schlemo@fixauto.com
Subject: For Your Kind Attention (Order ID: GUQCFV)
Attachment: Guqcufv_Signed_.img (contains "Guqcufv_Signed_.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Remcosrat
Status:
Malicious
First seen:
2020-07-13 12:03:05 UTC
AV detection:
16 of 29 (55.17%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

img 1bb377e6413d2aba9a88cea30057245d46780b96fa5c79d3b0333dd6306d7722

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments