MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ff2b3e3ad1db30f0f1d911d140871936223b5060dc729a61d784b9f76483f6f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3ff2b3e3ad1db30f0f1d911d140871936223b5060dc729a61d784b9f76483f6f
SHA3-384 hash: 0e64d57280087e45fef5d7bf3ff8b72455f5a7a379f9010b39351709ad1d9cf86ba082e5b0a4efcf9664c698efac1ec5
SHA1 hash: e4aa459389d366f94114193acc336f4b8b208ed6
MD5 hash: 9fd17890867c82bb9a56db7f818b2d79
humanhash: monkey-hydrogen-quiet-three
File name:QUOTE_8776_788965_998866PDF.IMG
Download: download sample
Signature AveMariaRAT
File size:1'507'328 bytes
First seen:2021-01-13 16:00:56 UTC
Last seen:Never
File type: img
MIME type:application/x-iso9660-image
ssdeep 12288:rMgpUpl0zbRTEE32hVBYyO0GeebJd9mFv6nnjqKoe:yl0zpHGhVBgeCHmV6nnjqKoe
TLSH B9655B426BC48700DBFD66FE6521006027E5EA6AF7BCD30CEE4560769FA2A5404FE793
Reporter abuse_ch
Tags:AveMariaRAT img RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: danaackremannl.com
Sending IP: 72.93.93.58
From: Lydia Yonkers<lydiayonkers@danaackremannl.com>
Reply-To: lydiayonkers@danaackremannl.com
Subject: Quote Request
Attachment: QUOTE_8776_788965_998866PDF.IMG (contains "QUOTE_8776_788965_998866PDF.exe")

AveMariaRAT C2:
warzon957.duckdns.org:5051 (45.141.58.213)

Intelligence


File Origin
# of uploads :
1
# of downloads :
162
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2021-01-13 16:01:05 UTC
AV detection:
5 of 46 (10.87%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

img 3ff2b3e3ad1db30f0f1d911d140871936223b5060dc729a61d784b9f76483f6f

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments