MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 352a15dc1e3ee770266d28c7a86bff3e099367919a9ce5fe694ce6c849806424. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 352a15dc1e3ee770266d28c7a86bff3e099367919a9ce5fe694ce6c849806424
SHA3-384 hash: 811a66a64b7214974c09519882d83607f9a6a6975fc6f6242b2410a78c30e3bd1347025f834265f39ceb70b3dd03587c
SHA1 hash: 1557fbf43f9b047e221a564af4545b8eb6129a90
MD5 hash: 75e264a27f0e065f790340734a7df009
humanhash: idaho-oranges-kilo-mango
File name:sample order.zip
Download: download sample
Signature AveMariaRAT
File size:415'955 bytes
First seen:2020-08-31 06:00:39 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:hbL3cMcPyRSuDIKDpxl8XJHXmE5ph/+LRbdpXatSrFdf4EC2gncxnZDFZVWDt8m+:5ccbx+ZNmRbdwtqrQQgncxndFbStxDUP
TLSH 5C9423231DD49FEC19BD82361F154D9FDDF499D6FE34C2B29E0AB80AC6A79642620C1C
Reporter abuse_ch
Tags:AveMariaRAT RAT zip


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: hwhk220-67.mailset.cn
Sending IP: 36.255.220.67
From: sherry <sherry@wengu168.com>
Subject: sample order
Attachment: sample order.zip (contains "Invoice.exe")

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
ByteCode-MSIL.Trojan.AveMariaRAT
Status:
Malicious
First seen:
2020-08-30 19:40:56 UTC
AV detection:
20 of 29 (68.97%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

zip 352a15dc1e3ee770266d28c7a86bff3e099367919a9ce5fe694ce6c849806424

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments