MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e92b2ec690517a1c426e3cb955d9347482d3a19dafc3a543de664b0acae116c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5e92b2ec690517a1c426e3cb955d9347482d3a19dafc3a543de664b0acae116c
SHA3-384 hash: d4ce434bb4184ab5e67eb1329b1c849b604c13af1d971d6755ff4b43621267c5bebe771ccd3e1f3d24451f4d33079243
SHA1 hash: 3614d3118add09359661edc6a1e84f81b98f31e9
MD5 hash: 1401cb434d5822e666d3c46ae8f8976a
humanhash: fix-summer-autumn-kentucky
File name:5e92b2ec690517a1c426e3cb955d9347482d3a19dafc3a543de664b0acae116c
Download: download sample
File size:6'422'850 bytes
First seen:2020-06-16 09:24:51 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 676f4bc1db7fb9f072b157186a10179e (1'400 x AveMariaRAT, 37 x Riskware.Generic, 2 x njrat)
ssdeep 49152:ATU7AAmw4gxeOw46fUbNecCCFbNecFTU7AAmw4gxeOw46fUbNecCCFbNecu:ATU7d9xZw46G8q8mTU7d9xZw46G8q87
Threatray 1'568 similar samples on MalwareBazaar
TLSH E6568ED2F83D805BE935B8709D0F5F00E65178199341FAAB2B317EAAC487289D2D774B
Reporter JAMESWT_WT

Intelligence


File Origin
# of uploads :
1
# of downloads :
63
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Spyware.AveMaria
Status:
Malicious
First seen:
2020-06-13 00:43:44 UTC
File Type:
PE (Exe)
Extracted files:
25
AV detection:
44 of 48 (91.67%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
persistence
Behaviour
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Suspicious behavior: EnumeratesProcesses
Drops file in Windows directory
Suspicious use of SetThreadContext
Adds Run entry to start application
Loads dropped DLL
Drops startup file
Executes dropped EXE
Modifies the visibility of hidden or system files
Modifies Installed Components in the registry
Modifies WinLogon for persistence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments