MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46efc6bb4c892aa18b8a2c9ef5f95d1701bb4f580e72ee35feecb09ebb2b6d72. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 46efc6bb4c892aa18b8a2c9ef5f95d1701bb4f580e72ee35feecb09ebb2b6d72
SHA3-384 hash: 351ad743acdefe840365d83cdd4d8f57e72bebde4d0dd3ba5ddb34e83d98371651d493430fd9bc12b059008140ac25a4
SHA1 hash: 0e45769cf8747a4ebbe23321cd2ce785fb11c427
MD5 hash: bc17f3e83d69de82a97cb103f3a5dc9b
humanhash: nevada-william-artist-princess
File name:Jordan offer.gz
Download: download sample
Signature AveMariaRAT
File size:37'796 bytes
First seen:2020-10-11 16:38:54 UTC
Last seen:Never
File type: gz
MIME type:application/x-rar
ssdeep 768:gu5UJP7wFONJJhxZ9KXgqeUkMf38v1r3gkO:9UJvNJ3owqiMfi1kX
TLSH 5803F1936CAEC992467B3762F178E934308377B208642737168A68DCC897E8B04EC196
Reporter abuse_ch
Tags:AveMariaRAT gz RAT


Avatar
abuse_ch
Malspam distributing AveMariaRAT:

HELO: slot0.globalsproducts.net
Sending IP: 45.95.169.130
From: info@globalsproducts.net
Subject: Jordan Shipment
Attachment: Jordan offer.gz (contains "Jordan offer.exe")

AveMariaRAT C2:
172.111.210.207:2829

Intelligence


File Origin
# of uploads :
1
# of downloads :
108
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Win32.Trojan.Bluteal
Status:
Malicious
First seen:
2020-10-11 15:43:09 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

gz 46efc6bb4c892aa18b8a2c9ef5f95d1701bb4f580e72ee35feecb09ebb2b6d72

(this sample)

  
Dropping
AveMariaRAT
  
Delivery method
Distributed via e-mail attachment

Comments