MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 448796b4712f0094eba10fe7913beda604f708b952b444ef446bd75a2953dc42. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
AveMariaRAT
Vendor detections: 4
| SHA256 hash: | 448796b4712f0094eba10fe7913beda604f708b952b444ef446bd75a2953dc42 |
|---|---|
| SHA3-384 hash: | cb3089bfcd030fe36b23ab52bcfbaad1227d303233c9ce5017954d046138fd1d7f65a3c7b1bf8a498c44fceab3e6a4f8 |
| SHA1 hash: | 84ecdc762af4822e6dd1219735ff2f08b81a1e79 |
| MD5 hash: | dfbe0879e629631cc3c2fef2ca292bb1 |
| humanhash: | comet-fifteen-avocado-fish |
| File name: | SHIPPING DOCUMENTS GST TAX pdf.zip |
| Download: | download sample |
| Signature | AveMariaRAT |
| File size: | 394'300 bytes |
| First seen: | 2020-12-10 11:10:50 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:DeCd3wvBKqeBZf5270d4A3jFK2o+iHyJ5PuuRe+7MBVythtKeISMCRWFKqPvDG:SCd3eeffqC4AM2WSX/v7EyH8XC4ZHDG |
| TLSH | E984232B52A5D14C7385E1B1CF9975EE023D9E8C809F18F4994B816CF82D4ABFB8C594 |
| Reporter | |
| Tags: | AveMariaRAT RAT zip |
abuse_ch
Malspam distributing AveMariaRAT:HELO: server.bwrobotlcs.com
Sending IP: 5.23.54.121
From: R Gunasekar - DSV <shippingrobots@bwrobotlcs.com>
Reply-To: R Gunasekar - DSV <saartrds.intl2@outlook.com>
Subject: RE : SHIPPING /CHECKLIST INV_PL_FCL_LCL - SI/EXP BL/CBM
Attachment: SHIPPING DOCUMENTS GST TAX pdf.zip (contains "SHIPPING DOCUMENTS GST TAX pdf.exe")
Intelligence
File Origin
# of uploads :
1
# of downloads :
191
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Result
Gathering data
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2020-12-10 11:11:09 UTC
AV detection:
9 of 48 (18.75%)
Threat level:
1/5
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
AveMariaRAT
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.