MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 383d02bfd4589eae7366cc19d39bf7e764baa20f19642a2c207c09e5596db892. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 383d02bfd4589eae7366cc19d39bf7e764baa20f19642a2c207c09e5596db892
SHA3-384 hash: 25971d4feec6d3cf29c56255afdd402a75dc18c37cf99f834a4853a2a47bae7a4c3c52c74992be7e347e26050d29bc82
SHA1 hash: ce35e2d377e459cd08d7d67d281a84ae15dba85d
MD5 hash: 57e2256fdd81c2cd9a0dbea263aea0e1
humanhash: alpha-neptune-arizona-pennsylvania
File name:OTCF-29102.iso
Download: download sample
Signature AveMariaRAT
File size:747'520 bytes
First seen:2020-11-11 10:19:17 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 12288:XVwpX4mPPPoAHEBaK/eueWl4qp48ZS24lx66V8gLWGLY:FuXZPPoEEBawenNCQw
TLSH FFF4C3472C7C46A7FF682770E82B1C14359FAD71AB3FA487976739215B730B1121EA0A
Reporter cocaman
Tags:AveMariaRAT iso


Avatar
cocaman
Malicious email (T1566.001)
From: "o.sacharuk@otcf.pl" (likely spoofed)
Received: "from mail.otcf.pl (mail.otcf.pl [83.238.62.214]) "
Date: "Wed, 11 Nov 2020 02:08:21 -0800"
Subject: "Payments For Invoices Done"
Attachment: "OTCF-29102.iso"

Intelligence


File Origin
# of uploads :
1
# of downloads :
72
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

iso 383d02bfd4589eae7366cc19d39bf7e764baa20f19642a2c207c09e5596db892

(this sample)

  
Delivery method
Distributed via e-mail attachment
  
Dropping
AveMariaRAT

Comments