MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66001328c8cfd8e691e5aa42cac1acb484280788b4bd4f05cc2f443e532e7af3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AveMariaRAT


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 66001328c8cfd8e691e5aa42cac1acb484280788b4bd4f05cc2f443e532e7af3
SHA3-384 hash: 91506182fba1c3413872b27dd6012ca67f01a8b87216670ddc8619423684512acbe747211c35ac81f4b1d8eb329455f4
SHA1 hash: 5607044f9c94cb80f45b9c40ec6da931d017d4a0
MD5 hash: 56c2ab10304f7db1560490a0b3036936
humanhash: indigo-mobile-hydrogen-july
File name:66001328c8cfd8e691e5aa42cac1acb484280788b4bd4f05cc2f443e532e7af3.rar
Download: download sample
Signature AveMariaRAT
File size:274'893 bytes
First seen:2020-05-14 09:16:06 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:fbzqCcRvy4mpRBkWYI3/qPdJg0xTFumVHKXGXjhnppstpqh:TzvqyvNLYICPdmmvVHKXynpytpG
TLSH 33442312D9D8AAF509066BEA4F01C72C382D7D6D7111740C6DE367BAAF5334AC4DCA39
Reporter JoulK
Tags:AveMariaRAT rar

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
Win32.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-14 09:35:34 UTC
File Type:
Binary (Archive)
Extracted files:
2
AV detection:
14 of 31 (45.16%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AveMariaRAT

rar 66001328c8cfd8e691e5aa42cac1acb484280788b4bd4f05cc2f443e532e7af3

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments